PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60575 Oracle Corporation CVE debrief

A vulnerability was discovered in Oracle Workflow, a component of Oracle E-Business Suite. The vulnerability is rated as medium severity with a CVSS score of 6.3. It affects versions 12.2.3-12.2.15 of Oracle Workflow. An attacker with low privileges and network access via HTTP could exploit this vulnerability to compromise Oracle Workflow, leading to unauthorized data access and partial denial of service.

Vendor
Oracle Corporation
Product
Oracle Workflow
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-27
Advisory published
2026-07-21
Advisory updated
2026-07-27

Who should care

Organizations using Oracle E-Business Suite versions 12.2.3-12.2.15 should prioritize patching this vulnerability to prevent potential exploitation. This is particularly important for operators and security teams responsible for maintaining system integrity and availability. Vulnerability management teams should assess the impact on their environments and plan for remediation. Additionally, platform administrators should review and update network access controls to limit exposure.

Technical summary

The vulnerability is located in the Workflow Notification Mailer component of Oracle Workflow. It has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L, indicating a medium severity impact on confidentiality, integrity, and availability. Successful attacks could result in unauthorized update, insert or delete access to some Oracle Workflow accessible data, unauthorized read access to a subset of Oracle Workflow accessible data, and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow.

Defensive priority

Medium priority should be given to patching this vulnerability due to its potential impact on data integrity and availability.

Recommended defensive actions

  • Apply the security patch provided by Oracle as soon as possible.
  • Review and update network access controls to limit exposure.
  • Monitor Oracle Workflow logs for suspicious activity.
  • Consider implementing additional security measures such as multi-factor authentication.
  • Perform a thorough review of system configurations and asset inventory to identify potential vulnerabilities.
  • Establish a rollback change window in case patching causes issues.
  • Track changes and verify source tracking for all updates.

Evidence notes

The CVE record was published on 2026-07-21T22:17:57.810Z and last modified on 2026-07-27T16:18:06.903Z. The NVD entry is currently Undergoing Analysis. Oracle has provided a security alert for this vulnerability (https://www.oracle.com/security-alerts/cpujul2026.html).

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:57.810Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.