PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60697 Oracle Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:10.373Z and has not been modified since then. The CVE-2026-60697 vulnerability is a medium-severity issue affecting Oracle E-Business Suite versions 12.2.3-12.2.15. It resides in the Site Hierarchy Flows component of Oracle Site Hub and allows low-privileged attackers with network access via HTTP to compromise Oracle Site Hub. Successful exploitation can lead to unauthorized data access, modification, and partial denial of service. The CVSS 3.1 Base Score is 6.3, with impacts on confidentiality, integrity, and availability. Oracle E-Business Suite administrators, security teams, and IT professionals responsible for managing and securing Oracle Site Hub should be aware of this vulnerability and take necessary actions to mitigate the risk.

Vendor
Oracle Corporation
Product
Oracle Site Hub
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-08-06
Advisory published
2026-07-21
Advisory updated
2026-08-06

Who should care

Oracle E-Business Suite administrators, security teams, and IT professionals responsible for managing and securing Oracle Site Hub should be aware of this vulnerability and take necessary actions to mitigate the risk.

Technical summary

The CVE-2026-60697 vulnerability is a medium-severity issue affecting Oracle E-Business Suite versions 12.2.3-12.2.15. It resides in the Site Hierarchy Flows component of Oracle Site Hub and allows low-privileged attackers with network access via HTTP to compromise Oracle Site Hub. Successful exploitation can lead to unauthorized data access, modification, and partial denial of service. The CVSS 3.1 Base Score is 6.3, with impacts on confidentiality, integrity, and availability.

Defensive priority

Medium priority given the CVSS score of 6.3 and the potential for unauthorized data access and partial denial of service.

Recommended defensive actions

  • Inventory and verify affected Oracle E-Business Suite versions
  • Apply vendor patches or updates as recommended by Oracle
  • Implement compensating controls to restrict network access to Oracle Site Hub
  • Monitor for suspicious activity and implement logging and auditing
  • Review and update security configurations for Oracle E-Business Suite

Evidence notes

The CVE-2026-60697 vulnerability affects Oracle E-Business Suite versions 12.2.3-12.2.15, specifically the Site Hierarchy Flows component of Oracle Site Hub. A low-privileged attacker with network access via HTTP can exploit this vulnerability. Successful attacks can lead to unauthorized update, insert, or delete access to some Oracle Site Hub data, unauthorized read access to a subset of Oracle Site Hub data, and partial denial of service. The CVSS 3.1 Base Score is 6.3, indicating medium severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:10.373Z and has not been modified since then.