Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60574

CVE-2026-60574: Oracle Content Manager Auth Bypass Flaw

CVE-2026-60574 is an authentication bypass vulnerability in Oracle Content Manager affecting versions 12.2.3-12.2.15. Attackers can gain unauthorized access to data and cause service disruption. This article covers technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2026-60574 Overview

CVE-2026-60574 is a vulnerability in the Oracle Content Manager component of Oracle E-Business Suite, specifically within the Cover Letter subcomponent. The flaw affects supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit the weakness to compromise Oracle Content Manager. Successful exploitation grants unauthorized update, insert, or delete access to a subset of Content Manager data, read access to a subset of accessible data, and the ability to cause a partial denial of service.

Critical Impact

Authenticated network-based attackers can modify, read, and partially disrupt Oracle Content Manager data through the Cover Letter component without user interaction.

Affected Products

  • Oracle E-Business Suite — Oracle Content Manager 12.2.3
  • Oracle E-Business Suite — Oracle Content Manager versions 12.2.4 through 12.2.14
  • Oracle E-Business Suite — Oracle Content Manager 12.2.15

Discovery Timeline

  • 2026-07-21 - CVE-2026-60574 published to NVD
  • 2026-07-21 - Last updated in NVD database
  • July 2026 - Addressed in the Oracle Critical Patch Update

Technical Details for CVE-2026-60574

Vulnerability Analysis

The vulnerability resides in the Cover Letter component of Oracle Content Manager, part of Oracle E-Business Suite. Oracle describes the issue as easily exploitable over HTTP, requiring only low privileges and no user interaction. Exploitation yields limited but real impacts across confidentiality, integrity, and availability of Content Manager data.

The EPSS score is 0.272% (percentile 19.234) as of 2026-07-23, indicating a low predicted probability of exploitation activity in the near term. No public proof-of-concept has been published, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

While Oracle has not released a detailed technical root-cause description, the impact profile — partial write, partial read, and partial denial of service — is consistent with a broken access control or input validation flaw within a specific Cover Letter request handler.

Root Cause

Oracle has not published the underlying root cause. Based on the impact scope, the defect likely involves missing or improper authorization checks on a Cover Letter HTTP endpoint accessible to authenticated Content Manager users. This class of flaw permits horizontal access to data owned by other users or workflows.

Attack Vector

The attack vector is network-based over HTTP. The attacker must hold a valid low-privilege account on the Oracle E-Business Suite instance. Once authenticated, the attacker issues crafted HTTP requests against the Cover Letter functionality to trigger unauthorized data operations against Content Manager records.

No verified exploit code is available. Refer to the Oracle Critical Patch Update advisory for July 2026 for vendor-provided technical detail.

Detection Methods for CVE-2026-60574

Indicators of Compromise

  • Unexpected create, update, or delete operations on Content Manager Cover Letter records originating from low-privileged user accounts.
  • Anomalous HTTP request volumes to Oracle Content Manager endpoints associated with Cover Letter functionality.
  • Database audit records showing modifications to Content Manager tables outside normal business workflows.

Detection Strategies

  • Enable and review Oracle E-Business Suite application-tier access logs for unusual Cover Letter component requests.
  • Correlate authenticated session activity against expected user roles to surface privilege boundary violations.
  • Baseline typical Content Manager write activity per user and alert on statistical deviations.

Monitoring Recommendations

  • Forward Oracle E-Business Suite HTTP and application logs to a centralized analytics platform for query and retention.
  • Monitor for repeated HTTP 4xx/5xx responses on Content Manager endpoints that may indicate probing.
  • Alert on any changes to Content Manager Cover Letter data performed outside approved change windows.

How to Mitigate CVE-2026-60574

Immediate Actions Required

  • Apply the fixes provided in the Oracle Critical Patch Update — July 2026 for all Oracle E-Business Suite deployments in the affected version range.
  • Inventory all Oracle E-Business Suite instances running versions 12.2.3 through 12.2.15 and prioritize patching for internet-exposed systems.
  • Review Content Manager user accounts and remove unnecessary low-privilege accounts that could be leveraged for exploitation.

Patch Information

Oracle addressed CVE-2026-60574 in the July 2026 Critical Patch Update. Administrators should follow the CPU documentation to apply patches for Oracle Content Manager on Oracle E-Business Suite versions 12.2.3 through 12.2.15. See the Oracle Critical Patch Update advisory for patch identifiers and installation instructions.

Workarounds

  • Restrict network access to Oracle E-Business Suite HTTP interfaces using firewall or reverse-proxy allow-lists until patching completes.
  • Enforce multi-factor authentication on all E-Business Suite accounts to raise the cost of credentialed exploitation.
  • Enable Oracle E-Business Suite auditing on Content Manager tables to capture forensic evidence of any exploitation attempts.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.