PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60867 Oracle Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:23.677Z and has not been modified since then. CVE-2026-60867 is a vulnerability in Oracle Advanced Pricing, allowing low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. Affected versions are 12.2.3-12.2.15. CVSS 3.1 score is 8.1, indicating high severity. The vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Pricing accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data. Oracle Advanced Pricing users should review and update access controls for low-privileged users, restrict network access to Pricing Installation, and ensure patches are applied to prevent exploitation. Evidence is limited to CVE and NVD details.

Vendor
Oracle Corporation
Product
Oracle Advanced Pricing
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-29
Advisory published
2026-07-21
Advisory updated
2026-07-29

Who should care

Oracle E-Business Suite users with Advanced Pricing component, security teams monitoring Oracle products, and administrators responsible for patching and vulnerability management should prioritize patching for affected versions 12.2.3-12.2.15. These stakeholders should review and update access controls for low-privileged users, restrict network access to Pricing Installation, and ensure patches are applied to prevent exploitation.

Technical summary

CVE-2026-60867 is a vulnerability in Oracle Advanced Pricing, allowing low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. Affected versions are 12.2.3-12.2.15. CVSS 3.1 score is 8.1, indicating high severity. The vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Pricing accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data.

Defensive priority

Oracle Advanced Pricing vulnerability allows low-privileged attackers to compromise data integrity and confidentiality; prioritize patching for affected versions 12.2.3-12.2.15.

Recommended defensive actions

  • Verify inventory for Oracle Advanced Pricing versions 12.2.3-12.2.15
  • Apply patches from Oracle
  • Monitor for unauthorized data modifications
  • Restrict network access to Pricing Installation
  • Review and update access controls for low-privileged users
  • Track exceptions and retest remediated assets
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE-2026-60867 vulnerability affects Oracle Advanced Pricing versions 12.2.3-12.2.15; verify inventory for affected versions and apply vendor patches; monitor for unauthorized data modifications. The vulnerability allows low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. Oracle Advanced Pricing users should review and update access controls for low-privileged users, restrict network access to Pricing Installation, and ensure patches are applied. Evidence is limited to CVE and NVD details.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:23.677Z and has not been modified since then.