PatchSiren cyber security CVE debrief
CVE-2026-60697 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:10.373Z and has not been modified since then. The CVE-2026-60697 vulnerability is a medium-severity issue affecting Oracle E-Business Suite versions 12.2.3-12.2.15. It resides in the Site Hierarchy Flows component of Oracle Site Hub and allows low-privileged attackers with network access via HTTP to compromise Oracle Site Hub. Successful exploitation can lead to unauthorized data access, modification, and partial denial of service. The CVSS 3.1 Base Score is 6.3, with impacts on confidentiality, integrity, and availability. Oracle E-Business Suite administrators, security teams, and IT professionals responsible for managing and securing Oracle Site Hub should be aware of this vulnerability and take necessary actions to mitigate the risk.
- Vendor
- Oracle Corporation
- Product
- Oracle Site Hub
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-06
Who should care
Oracle E-Business Suite administrators, security teams, and IT professionals responsible for managing and securing Oracle Site Hub should be aware of this vulnerability and take necessary actions to mitigate the risk.
Technical summary
The CVE-2026-60697 vulnerability is a medium-severity issue affecting Oracle E-Business Suite versions 12.2.3-12.2.15. It resides in the Site Hierarchy Flows component of Oracle Site Hub and allows low-privileged attackers with network access via HTTP to compromise Oracle Site Hub. Successful exploitation can lead to unauthorized data access, modification, and partial denial of service. The CVSS 3.1 Base Score is 6.3, with impacts on confidentiality, integrity, and availability.
Defensive priority
Medium priority given the CVSS score of 6.3 and the potential for unauthorized data access and partial denial of service.
Recommended defensive actions
- Inventory and verify affected Oracle E-Business Suite versions
- Apply vendor patches or updates as recommended by Oracle
- Implement compensating controls to restrict network access to Oracle Site Hub
- Monitor for suspicious activity and implement logging and auditing
- Review and update security configurations for Oracle E-Business Suite
Evidence notes
The CVE-2026-60697 vulnerability affects Oracle E-Business Suite versions 12.2.3-12.2.15, specifically the Site Hierarchy Flows component of Oracle Site Hub. A low-privileged attacker with network access via HTTP can exploit this vulnerability. Successful attacks can lead to unauthorized update, insert, or delete access to some Oracle Site Hub data, unauthorized read access to a subset of Oracle Site Hub data, and partial denial of service. The CVSS 3.1 Base Score is 6.3, indicating medium severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-60697 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-60697
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-60697 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-60697
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cpujul2026.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.