Sceawere

Vulnerability Detail

CVE-2026-60880Updated Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Work in Process Takeover

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
Oracle Corporation
Product
Oracle Work in Process
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-07-21T22:18:24.480Z",
  "pubdate": "2026-07-21T22:18:24.480Z",
  "executiveSummary": "A critical vulnerability has been identified within the Internal Operations component of Oracle Work in Process, a module of the Oracle E-Business Suite. The vulnerability is classified as highly exploitable, allowing an unauthenticated remote attacker to achieve full system compromise.\nThe flaw possesses a CVSS 3.1 base score of 9.8, indicating severe risks to confidentiality, integrity, and availability. Impacted versions span from 12.2.3 through 12.2.15. The exploitation does not require user interaction or prior authentication, enabling an attacker with network access via HTTP to execute arbitrary operations or commands within the target environment.\nThis vulnerability presents a significant risk to the integrity of manufacturing and production data managed within Oracle E-Business Suite. Successful exploitation grants the attacker complete control over the affected component, potentially leading to unauthorized data exfiltration, manipulation of business-critical process records, and total service disruption. Organizations utilizing these versions of Oracle Work in Process are at substantial risk and should prioritize immediate mitigation strategies.",
  "technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle Work in Process. It stems from improper input validation or insufficient authorization checks that allow unauthenticated remote entities to interact with sensitive administrative or functional interfaces. Because the vulnerability is exposed over HTTP, any reachable instance of the Oracle E-Business Suite within the specified version range (12.2.3-12.2.15) is susceptible to exploitation.\nThe attack flow begins with the attacker identifying the network-accessible interface associated with Internal Operations. By crafting specific HTTP requests, the attacker bypasses standard authentication mechanisms that are expected to gatekeep such internal administrative functions. Since the system fails to enforce authentication at the component level, the malicious request is processed as a legitimate transaction or operation.\nThe exploitation method leverages the lack of robust request validation to invoke backend functions that were intended only for authenticated system administrators or internal system processes. Once the initial unauthorized request is processed, the attacker can leverage the application's internal privileges to manipulate underlying database objects, business workflows, or configuration parameters related to the Work in Process module. This effectively grants the attacker the ability to perform any action permitted by the application's internal service account.\nThe post-exploitation impact is total compromise. An attacker can move beyond simple data retrieval and actively modify production schedules, alter work orders, or execute arbitrary code if the underlying application logic permits function chaining or code injection. By compromising the Internal Operations component, the attacker achieves an level of access equivalent to that of an authenticated administrative user, facilitating the exfiltration of sensitive manufacturing data and the subversion of internal business logic. The combination of network-level reachability (AV:N), low complexity (AC:L), and zero-privilege requirement (PR:N) classifies this as a critical path to full application takeover."
}
CVE-2026-60880: Oracle Work in Process Takeover (CRITICAL Severity, CVSS: 9.8) - Sceawere