PatchSiren cyber security CVE debrief
CVE-2026-60867 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:23.677Z and has not been modified since then. CVE-2026-60867 is a vulnerability in Oracle Advanced Pricing, allowing low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. Affected versions are 12.2.3-12.2.15. CVSS 3.1 score is 8.1, indicating high severity. The vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Pricing accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data. Oracle Advanced Pricing users should review and update access controls for low-privileged users, restrict network access to Pricing Installation, and ensure patches are applied to prevent exploitation. Evidence is limited to CVE and NVD details.
- Vendor
- Oracle Corporation
- Product
- Oracle Advanced Pricing
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-29
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-29
Who should care
Oracle E-Business Suite users with Advanced Pricing component, security teams monitoring Oracle products, and administrators responsible for patching and vulnerability management should prioritize patching for affected versions 12.2.3-12.2.15. These stakeholders should review and update access controls for low-privileged users, restrict network access to Pricing Installation, and ensure patches are applied to prevent exploitation.
Technical summary
CVE-2026-60867 is a vulnerability in Oracle Advanced Pricing, allowing low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. Affected versions are 12.2.3-12.2.15. CVSS 3.1 score is 8.1, indicating high severity. The vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Pricing accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data.
Defensive priority
Oracle Advanced Pricing vulnerability allows low-privileged attackers to compromise data integrity and confidentiality; prioritize patching for affected versions 12.2.3-12.2.15.
Recommended defensive actions
- Verify inventory for Oracle Advanced Pricing versions 12.2.3-12.2.15
- Apply patches from Oracle
- Monitor for unauthorized data modifications
- Restrict network access to Pricing Installation
- Review and update access controls for low-privileged users
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE-2026-60867 vulnerability affects Oracle Advanced Pricing versions 12.2.3-12.2.15; verify inventory for affected versions and apply vendor patches; monitor for unauthorized data modifications. The vulnerability allows low-privileged attackers with network access via HTTP to compromise data integrity and confidentiality. Oracle Advanced Pricing users should review and update access controls for low-privileged users, restrict network access to Pricing Installation, and ensure patches are applied. Evidence is limited to CVE and NVD details.
Official resources
-
CVE-2026-60867 CVE record
CVE.org
-
CVE-2026-60867 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:23.677Z and has not been modified since then.