PatchSiren cyber security CVE debrief
CVE-2026-60972 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:30.777Z and has not been modified since then. The CVE-2026-60972 vulnerability affects Oracle E-Business Tax versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data creation, deletion, or modification. The CVSS 3.1 Base Score is 8.1, indicating a high severity level, with Confidentiality and Integrity impacts. Organizations should review and apply Oracle's security patches for E-Business Tax versions 12.2.3-12.2.15. The vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle E-Business Tax, resulting in unauthorized creation, deletion, or modification access to critical data or all Oracle E-Business Tax accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data.
- Vendor
- Oracle Corporation
- Product
- Oracle E-Business Tax
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-31
Who should care
Organizations using Oracle E-Business Tax versions 12.2.3-12.2.15 should prioritize patching this vulnerability to prevent potential data breaches. Affected operators and platforms should review and apply Oracle's security patches. Vulnerability management and security teams should monitor Oracle E-Business Tax systems for suspicious activity and implement compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent attacks. Inventory of Oracle E-Business Tax installations should be verified and ensured to be up-to-date.
Technical summary
The CVE-2026-60972 vulnerability affects Oracle E-Business Tax versions 12.2.3-12.2.15. It is an easily exploitable vulnerability that allows low-privileged attackers with network access via HTTP to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data. The CVSS 3.1 Base Score is 8.1, indicating a high severity level, with Confidentiality and Integrity impacts.
Defensive priority
Oracle E-Business Tax vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data creation, deletion, or modification.
Recommended defensive actions
- Review and apply Oracle's security patches for E-Business Tax versions 12.2.3-12.2.15.
- Restrict network access to Oracle E-Business Tax to only necessary personnel.
- Monitor Oracle E-Business Tax systems for suspicious activity.
- Implement compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent attacks.
- Verify inventory of Oracle E-Business Tax installations and ensure they are up-to-date.
Evidence notes
The CVE-2026-60972 vulnerability affects Oracle E-Business Tax versions 12.2.3-12.2.15. It allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle E-Business Tax accessible data, as well as unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data. The CVSS 3.1 Base Score is 8.1, indicating a high severity level.
Official resources
-
CVE-2026-60972 CVE record
CVE.org
-
CVE-2026-60972 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:30.777Z and has not been modified since then.