PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60870 Oracle Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:23.910Z and has not been modified since then. CVE-2026-60870 is a vulnerability in Oracle Advanced Pricing, a component of Oracle E-Business Suite. This vulnerability allows low-privileged attackers with network access via HTTP to compromise the confidentiality and integrity of data. The affected versions of Oracle Advanced Pricing are 12.2.3-12.2.15, and the CVSS 3.1 score is 7.1. The vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data, as well as unauthorized update, insert, or delete access to some of Oracle Advanced Pricing accessible data. To address this vulnerability, defenders should verify inventory for Oracle Advanced Pricing versions 12.2.3-12.2.15, apply patches from Oracle as available, monitor for unauthorized access attempts, restrict network access to Oracle Advanced Pricing, review and update access controls for low-privileged users, conduct vulnerability scanning for Oracle E-Business Suite deployments, and review system logs for potential security incidents.

Vendor
Oracle Corporation
Product
Oracle Advanced Pricing
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-29
Advisory published
2026-07-21
Advisory updated
2026-07-29

Who should care

Oracle E-Business Suite users with Advanced Pricing component, security teams monitoring Oracle products, low-privileged users with network access to Oracle Advanced Pricing, and IT administrators responsible for patch management and vulnerability remediation.

Technical summary

CVE-2026-60870 is a vulnerability in Oracle Advanced Pricing, allowing low-privileged attackers with network access via HTTP to compromise confidentiality and integrity. Affected versions are 12.2.3-12.2.15; CVSS 3.1 score is 7.1. The vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Pricing accessible data as well as unauthorized update, insert or delete access to some of Oracle Advanced Pricing accessible data.

Defensive priority

Oracle Advanced Pricing vulnerability allows low-privileged attackers to compromise data confidentiality and integrity; prioritize patching for affected versions 12.2.3-12.2.15.

Recommended defensive actions

  • Verify inventory for Oracle Advanced Pricing versions 12.2.3-12.2.15
  • Apply patches from Oracle as available
  • Monitor for unauthorized access attempts
  • Restrict network access to Oracle Advanced Pricing
  • Review and update access controls for low-privileged users
  • Conduct vulnerability scanning for Oracle E-Business Suite deployments
  • Review system logs for potential security incidents

Evidence notes

The CVE-2026-60870 vulnerability affects Oracle Advanced Pricing versions 12.2.3-12.2.15. To verify inventory for affected versions, defenders should check for Oracle E-Business Suite deployments with Advanced Pricing components. Evidence is limited to CVE and NVD details. Monitor for patch deployment and unauthorized access attempts. Verify affected versions and review access controls for low-privileged users.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:23.910Z and has not been modified since then.