PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60972 Oracle Corporation CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:30.777Z and has not been modified since then. The CVE-2026-60972 vulnerability affects Oracle E-Business Tax versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data creation, deletion, or modification. The CVSS 3.1 Base Score is 8.1, indicating a high severity level, with Confidentiality and Integrity impacts. Organizations should review and apply Oracle's security patches for E-Business Tax versions 12.2.3-12.2.15. The vulnerability allows low-privileged attackers with network access via HTTP to compromise Oracle E-Business Tax, resulting in unauthorized creation, deletion, or modification access to critical data or all Oracle E-Business Tax accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data.

Vendor
Oracle Corporation
Product
Oracle E-Business Tax
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-31
Advisory published
2026-07-21
Advisory updated
2026-07-31

Who should care

Organizations using Oracle E-Business Tax versions 12.2.3-12.2.15 should prioritize patching this vulnerability to prevent potential data breaches. Affected operators and platforms should review and apply Oracle's security patches. Vulnerability management and security teams should monitor Oracle E-Business Tax systems for suspicious activity and implement compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent attacks. Inventory of Oracle E-Business Tax installations should be verified and ensured to be up-to-date.

Technical summary

The CVE-2026-60972 vulnerability affects Oracle E-Business Tax versions 12.2.3-12.2.15. It is an easily exploitable vulnerability that allows low-privileged attackers with network access via HTTP to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data as well as unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data. The CVSS 3.1 Base Score is 8.1, indicating a high severity level, with Confidentiality and Integrity impacts.

Defensive priority

Oracle E-Business Tax vulnerability allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data creation, deletion, or modification.

Recommended defensive actions

  • Review and apply Oracle's security patches for E-Business Tax versions 12.2.3-12.2.15.
  • Restrict network access to Oracle E-Business Tax to only necessary personnel.
  • Monitor Oracle E-Business Tax systems for suspicious activity.
  • Implement compensating controls, such as Web Application Firewalls (WAFs), to detect and prevent attacks.
  • Verify inventory of Oracle E-Business Tax installations and ensure they are up-to-date.

Evidence notes

The CVE-2026-60972 vulnerability affects Oracle E-Business Tax versions 12.2.3-12.2.15. It allows low-privileged attackers with network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle E-Business Tax accessible data, as well as unauthorized access to critical data or complete access to all Oracle E-Business Tax accessible data. The CVSS 3.1 Base Score is 8.1, indicating a high severity level.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:30.777Z and has not been modified since then.