Sceawere

Vulnerability Detail

CVE-2026-60773Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle E-Business Suite Privilege Escalation

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.6
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Application Object Library
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.6",
  "pubDate": "2026-07-21T22:18:16.443Z",
  "pubdate": "2026-07-21T22:18:16.443Z",
  "executiveSummary": "This vulnerability affects the Oracle Application Object Library component within Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15.\nThe vulnerability is classified as a critical security flaw involving a scope change, which allows a low-privileged authenticated attacker to gain unauthorized access and manipulation capabilities across the system.\nDue to the nature of the vulnerability, an attacker with network access via HTTPS can compromise the integrity and confidentiality of critical data.\nThe vulnerability carries a CVSS 3.1 Base Score of 9.6, reflecting the severe potential for unauthorized data creation, modification, and deletion.\nThe impact extends beyond the Oracle Application Object Library due to the scope change (S:C), potentially affecting integrated or secondary products within the E-Business Suite environment.\nSuccessful exploitation requires minimal effort from the attacker, as the complexity is low and no user interaction is necessary to execute the attack.",
  "technicalDetails": "The vulnerability resides within the Oracle Application Object Library, a core component of the Oracle E-Business Suite architecture. The root cause pertains to an insufficient authorization or access control mechanism that fails to properly validate the scope of requests, leading to a cross-component impact.\nThe attack vector is identified as network-based (AV:N), specifically leveraging the HTTPS protocol. An attacker with low-level privileges (PR:L) can reach the vulnerable component over the network without the requirement of additional user interaction (UI:N).\nThe exploitation process follows a sequence where the attacker leverages legitimate, albeit low-privileged, access to the E-Business Suite environment. By crafting specific network requests aimed at the Oracle Application Object Library, the attacker triggers an improper authorization check that facilitates a scope change (S:C). This allows the attacker to bypass standard restrictions and interact with objects or data structures outside of their assigned security context.\nOnce the boundary is breached, the attacker can execute unauthorized actions, including the creation, modification, or deletion of sensitive information. Because the scope change impacts the overall security posture, the attacker can effectively manipulate critical data repositories within the Oracle Application Object Library and potentially influence broader system configurations or connected modules.\nThe technical impact is characterized by high confidentiality (C:H) and integrity (I:H) violations. The attacker essentially gains the ability to perform administrative-level CRUD (Create, Read, Update, Delete) operations on data that should be protected from low-privileged accounts. The vulnerability does not explicitly mention availability (A:N) impacts, suggesting the attack is primarily focused on data theft and unauthorized system state manipulation rather than service disruption.\nGiven the versions 12.2.3-12.2.15 are explicitly affected, the vulnerability likely stems from architectural changes or legacy code integration within the application framework that fail to enforce strict object-level security during cross-component communication."
}
CVE-2026-60773: Oracle E-Business Suite Privilege Escalation (CRITICAL Severity, CVSS: 9.6) - Sceawere