PatchSiren cyber security CVE debrief
CVE-2026-60870 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:23.910Z and has not been modified since then. CVE-2026-60870 is a vulnerability in Oracle Advanced Pricing, a component of Oracle E-Business Suite. This vulnerability allows low-privileged attackers with network access via HTTP to compromise the confidentiality and integrity of data. The affected versions of Oracle Advanced Pricing are 12.2.3-12.2.15, and the CVSS 3.1 score is 7.1. The vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data, as well as unauthorized update, insert, or delete access to some of Oracle Advanced Pricing accessible data. To address this vulnerability, defenders should verify inventory for Oracle Advanced Pricing versions 12.2.3-12.2.15, apply patches from Oracle as available, monitor for unauthorized access attempts, restrict network access to Oracle Advanced Pricing, review and update access controls for low-privileged users, conduct vulnerability scanning for Oracle E-Business Suite deployments, and review system logs for potential security incidents.
- Vendor
- Oracle Corporation
- Product
- Oracle Advanced Pricing
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-29
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-29
Who should care
Oracle E-Business Suite users with Advanced Pricing component, security teams monitoring Oracle products, low-privileged users with network access to Oracle Advanced Pricing, and IT administrators responsible for patch management and vulnerability remediation.
Technical summary
CVE-2026-60870 is a vulnerability in Oracle Advanced Pricing, allowing low-privileged attackers with network access via HTTP to compromise confidentiality and integrity. Affected versions are 12.2.3-12.2.15; CVSS 3.1 score is 7.1. The vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data.
Defensive priority
Oracle Advanced Pricing vulnerability allows low-privileged attackers to compromise data confidentiality and integrity; prioritize patching for affected versions 12.2.3-12.2.15.
Recommended defensive actions
- Verify inventory for Oracle Advanced Pricing versions 12.2.3-12.2.15
- Apply patches from Oracle as available
- Monitor for unauthorized access attempts
- Restrict network access to Oracle Advanced Pricing
- Review and update access controls for low-privileged users
- Conduct vulnerability scanning for Oracle E-Business Suite deployments
- Review system logs for potential security incidents
Evidence notes
The CVE-2026-60870 vulnerability affects Oracle Advanced Pricing versions 12.2.3-12.2.15. To verify inventory for affected versions, defenders should check for Oracle E-Business Suite deployments with Advanced Pricing components. Evidence is limited to CVE and NVD details. Monitor for patch deployment and unauthorized access attempts. Verify affected versions and review access controls for low-privileged users.
Official resources
-
CVE-2026-60870 CVE record
CVE.org
-
CVE-2026-60870 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:23.910Z and has not been modified since then.