PatchSiren cyber security CVE debrief
CVE-2026-60735 Oracle CVE debrief
A HIGH severity vulnerability was found in Oracle Sales Offline, a component of Oracle E-Business Suite. The vulnerability has a CVSS 3.1 Base Score of 8.1 and can be easily exploited by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized creation, deletion, or modification of critical data. The vulnerability affects versions 12.2.3-12.2.15 of Oracle Sales Offline. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N. This vulnerability may lead to significant data breaches if not addressed promptly.
- Vendor
- Oracle
- Product
- Sales Offline
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Organizations using Oracle Sales Offline versions 12.2.3-12.2.15 should prioritize patching this vulnerability to prevent potential data breaches. The vulnerability's HIGH severity and ease of exploitation make it a critical concern for affected users. Security teams and administrators responsible for Oracle E-Business Suite deployments should review the official advisory and take immediate action to mitigate the risk.
Technical summary
The vulnerability in Oracle Sales Offline (component: Internal Operations) allows an attacker with low privileges and network access via HTTP to compromise the system. Successful attacks can result in unauthorized creation, deletion, or modification access to critical data or all Oracle Sales Offline accessible data, as well as unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. The CVSS Vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N. The vulnerability has a CVSS 3.1 Base Score of 8.1, indicating a HIGH severity vulnerability.
Defensive priority
Apply patches or mitigations provided by Oracle as soon as possible to prevent exploitation. Restrict network access to the affected system and monitor for suspicious activity.
Recommended defensive actions
- Apply the patch provided by Oracle
- Restrict network access to the affected system
- Monitor for suspicious activity
- Review and update access controls
- Perform a thorough review of the system for any signs of compromise
- Implement compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions and retest remediated assets
Evidence notes
The CVE record was published on 2026-07-21T22:18:13.987Z and was last modified on 2026-07-27T17:33:30.217Z. The NVD entry is currently Analyzed. This information is based on the NVD entry and the CVE record. The vulnerability affects Oracle Sales Offline, a component of Oracle E-Business Suite, with versions 12.2.3-12.2.15 being vulnerable. The CVSS 3.1 Base Score is 8.1, indicating a HIGH severity vulnerability. The vulnerability allows an attacker with low privileges and network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. The evidence provided is limited, and defenders should verify the affected scope and severity based on the official advisory.
Official resources
-
CVE-2026-60735 CVE record
CVE.org
-
CVE-2026-60735 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:13.987Z and has not been modified since then. The NVD entry is currently Analyzed.