PatchSiren cyber security CVE debrief
CVE-2026-60574 Oracle Corporation CVE debrief
A vulnerability was discovered in Oracle Content Manager, a component of Oracle E-Business Suite. The vulnerability is rated as Medium with a CVSS score of 6.3. It allows a low-privileged attacker with network access via HTTP to compromise Oracle Content Manager, potentially leading to unauthorized data access and partial denial of service. The vulnerability is located in the Cover Letter component of Oracle Content Manager. Successful attacks can result in unauthorized update, insert or delete access to some Oracle Content Manager accessible data, unauthorized read access to a subset of Oracle Content Manager accessible data, and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Content Manager. Organizations using Oracle E-Business Suite, specifically those with Oracle Content Manager in use, should be aware of this vulnerability and take necessary actions to protect their systems. The CVE record was published on 2026-07-21T22:17:57.700Z and last modified on 2026-07-27T16:18:06.800Z. The NVD entry is currently Undergoing Analysis.
- Vendor
- Oracle Corporation
- Product
- Oracle Content Manager
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Organizations using Oracle E-Business Suite, specifically those with Oracle Content Manager in use, should be aware of this vulnerability and take necessary actions to protect their systems.
Technical summary
The vulnerability is located in the Cover Letter component of Oracle Content Manager. It has a CVSS Vector of (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L), indicating a Medium severity. Successful attacks can result in unauthorized update, insert or delete access to some Oracle Content Manager accessible data, unauthorized read access to a subset of Oracle Content Manager accessible data, and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Content Manager.
Defensive priority
Apply vendor patches or updates as soon as possible. Restrict network access to Oracle Content Manager to only necessary personnel. Monitor Oracle Content Manager logs for suspicious activity and perform regular security audits and vulnerability assessments to ensure system integrity. Implement compensating controls for exposed systems while remediation is scheduled and verified. Track exceptions, retest remediated assets, and close the item only after evidence is documented. Review relevant monitoring, detection, and logs for exposed assets that need extra review. Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Recommended defensive actions
- Apply the Oracle patch for CVE-2026-60574.
- Restrict network access to Oracle Content Manager.
- Monitor Oracle Content Manager logs for suspicious activity.
- Perform regular security audits and vulnerability assessments.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE record was published on 2026-07-21T22:17:57.700Z and last modified on 2026-07-27T16:18:06.800Z. The NVD entry is currently Undergoing Analysis. The vulnerability has a CVSS score of 6.3 and is rated as Medium. The CVE details are based on information from Oracle and NVD. However, due to limited source detail, the impact and affected scope should be verified with defensive testing and evidence-limited analysis.
Official resources
-
CVE-2026-60574 CVE record
CVE.org
-
CVE-2026-60574 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:57.700Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.