CVE-2026-60587 Overview
CVE-2026-60587 is a vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite, specifically within the Project Definition component. Affected versions span 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit this flaw to compromise Oracle Project Foundation. Successful exploitation grants unauthorized update, insert, or delete access to a subset of application data, unauthorized read access to a subset of application data, and the ability to cause a partial denial of service.
Critical Impact
Authenticated network attackers can modify and read portions of Oracle Project Foundation data and trigger partial denial of service against affected E-Business Suite deployments.
Affected Products
- Oracle E-Business Suite — Oracle Project Foundation 12.2.3
- Oracle E-Business Suite — Oracle Project Foundation 12.2.4 through 12.2.14
- Oracle E-Business Suite — Oracle Project Foundation 12.2.15
Discovery Timeline
- 2026-07-21 - CVE-2026-60587 published to NVD
- 2026-07-21 - Last updated in NVD database
Technical Details for CVE-2026-60587
Vulnerability Analysis
The vulnerability resides in the Project Definition component of Oracle Project Foundation, a module of Oracle E-Business Suite. The flaw is described as easily exploitable and requires only a low-privileged authenticated account with HTTP access to the application tier. Impacts fall across confidentiality, integrity, and availability, but each dimension is limited in scope. An attacker can obtain read access to a subset of accessible data, modify a subset of accessible data through unauthorized insert, update, or delete operations, and induce a partial denial of service against the Project Foundation service.
Root Cause
Oracle has not published component-level technical details for CVE-2026-60587. The advisory attributes the issue to the Project Definition component of Oracle Project Foundation. The combination of low required privileges, no user interaction, and unchanged scope indicates a server-side access control or input handling weakness reachable through authenticated HTTP requests to Project Foundation endpoints.
Attack Vector
Exploitation occurs over the network using HTTP against the Oracle E-Business Suite application tier. The attacker must hold valid low-privilege credentials within the environment. No user interaction is required, and the attack does not cross a trust boundary beyond the vulnerable component. Refer to the Oracle Security Alert July 2026 for authoritative details.
Detection Methods for CVE-2026-60587
Indicators of Compromise
- Unexpected create, update, or delete operations in Oracle Project Foundation audit tables performed by low-privileged accounts.
- Anomalous HTTP request patterns to Project Definition endpoints from accounts that do not normally interact with project data.
- Repeated errors or service degradation in Project Foundation logs consistent with partial denial of service.
Detection Strategies
- Enable Oracle E-Business Suite auditing on Project Foundation tables and review changes performed outside normal business workflows.
- Correlate application-tier HTTP access logs with database DML events to surface unauthorized modifications tied to specific sessions.
- Baseline expected user access to Project Definition functionality and alert on deviations by role or user population.
Monitoring Recommendations
- Forward Oracle E-Business Suite application, database, and web tier logs to a centralized analytics platform for query and retention.
- Track authentication and privilege usage of low-privileged accounts that have any access to Project Foundation modules.
- Alert on spikes in HTTP 5xx responses or backend errors originating from Project Definition URLs, which may indicate partial DoS attempts.
How to Mitigate CVE-2026-60587
Immediate Actions Required
- Apply the fixes published in the Oracle Critical Patch Update — July 2026 to all affected Oracle E-Business Suite environments.
- Inventory all Oracle E-Business Suite installations running versions 12.2.3 through 12.2.15 and prioritize patching for internet-exposed instances.
- Review Project Foundation role assignments and remove unnecessary access from accounts that do not require project data.
Patch Information
Oracle addresses CVE-2026-60587 in the July 2026 Critical Patch Update. Administrators should download and apply the Project Foundation patches referenced in the Oracle Security Alert July 2026 after validating them in a non-production environment.
Workarounds
- Restrict network access to the Oracle E-Business Suite application tier so that only trusted internal networks and VPN clients can reach HTTP endpoints.
- Enforce least-privilege responsibilities and menus in Oracle E-Business Suite so that only required users can invoke Project Definition functionality.
- Increase logging and monitoring around Project Foundation until the vendor patch is applied across all instances.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

