PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60987 Oracle CVE debrief

CVE-2026-60987 is a vulnerability in Oracle Project Portfolio Analysis, a component of Oracle E-Business Suite. The vulnerability class is related to internal operations and allows low-privileged attackers with network access via HTTP to compromise the system. The likely operational impact includes unauthorized creation, deletion, or modification access to critical data or all Oracle Project Portfolio Analysis accessible data, as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data. The source-confidence limits are based on the CVE record and NVD detail, which indicate a high CVSS score of 7.1, reflecting its potential impact on confidentiality and integrity. The review context suggests that organizations should prioritize patching and monitoring to prevent potential exploitation. This includes reviewing and applying Oracle's security patches, restricting network access, and monitoring for suspicious activity. Additionally, organizations should verify and limit privileges of users with access to Project Portfolio Analysis and conduct a thorough review of the affected system's exposure.

Vendor
Oracle
Product
Project Portfolio Analysis
CVSS
HIGH 7.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-31
Advisory published
2026-07-21
Advisory updated
2026-07-31

Who should care

Organizations using Oracle Project Portfolio Analysis versions 12.2.3-12.2.15 should prioritize patching and monitoring to prevent potential exploitation. This includes reviewing and applying Oracle's security patches, restricting network access, and monitoring for suspicious activity. Additionally, organizations should verify and limit privileges of users with access to Project Portfolio Analysis and conduct a thorough review of the affected system's exposure. Security teams and vulnerability management teams should also be aware of the potential impact of this vulnerability on their systems and take necessary steps to mitigate it.

Technical summary

CVE-2026-60987 is a vulnerability in Oracle Project Portfolio Analysis, allowing low-privileged attackers with network access via HTTP to compromise the system, leading to unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to a subset of data. The vulnerability has a CVSS score of 7.1, indicating a high level of severity. The affected versions of Oracle Project Portfolio Analysis are 12.2.3-12.2.15. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized read access to a subset of Oracle Project Portfolio Analysis accessible data.

Defensive priority

Oracle Project Portfolio Analysis vulnerability allows low-privileged attackers to compromise data integrity and confidentiality.

Recommended defensive actions

  • Review and apply Oracle's security patches for Project Portfolio Analysis
  • Restrict network access to Project Portfolio Analysis
  • Monitor Project Portfolio Analysis for suspicious activity
  • Verify and limit privileges of users with access to Project Portfolio Analysis
  • Conduct a thorough review of the affected system's exposure and implement compensating controls if necessary
  • Perform asset inventory to identify all instances of Oracle Project Portfolio Analysis
  • Track exceptions and retest remediated assets to ensure the vulnerability is properly mitigated

Evidence notes

The CVE-2026-60987 vulnerability affects Oracle Project Portfolio Analysis versions 12.2.3-12.2.15, allowing low-privileged attackers with network access via HTTP to compromise the system. Evidence from the CVE record and NVD detail indicate that this vulnerability has a high CVSS score of 7.1, reflecting its potential impact on confidentiality and integrity. Defenders should verify the presence of affected product deployments in their environments and review official advisories for mitigation guidance. The vulnerability's scope and severity suggest that organizations should prioritize patching and monitoring to prevent potential exploitation.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:18:31.797Z and has not been modified since then.