Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60735

CVE-2026-60735: Oracle Sales Offline Auth Bypass Flaw

CVE-2026-60735 is an authentication bypass vulnerability in Oracle Sales Offline that enables unauthorized data access and modification. This article covers the technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-60735 Overview

CVE-2026-60735 is a high-severity vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite, within the Internal Operations component. The flaw affects supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit the weakness without user interaction. Successful exploitation permits unauthorized creation, deletion, or modification of Oracle Sales Offline data, along with unauthorized read access to all data accessible through the product. Oracle disclosed the issue in its July 2026 Critical Patch Update.

Critical Impact

Authenticated network attackers can read, alter, or destroy any data accessible through Oracle Sales Offline, undermining the confidentiality and integrity of Oracle E-Business Suite records.

Affected Products

  • Oracle E-Business Suite — Oracle Sales Offline 12.2.3
  • Oracle E-Business Suite — Oracle Sales Offline versions 12.2.4 through 12.2.14
  • Oracle E-Business Suite — Oracle Sales Offline 12.2.15

Discovery Timeline

  • 2026-07-21 - CVE-2026-60735 published to NVD
  • 2026-07-21 - Last updated in NVD database
  • July 2026 - Oracle addresses the issue in the Oracle Security Alert July 2026

Technical Details for CVE-2026-60735

Vulnerability Analysis

The vulnerability resides in the Internal Operations component of Oracle Sales Offline, a module within Oracle E-Business Suite. An authenticated user with minimal privileges can send crafted HTTP requests to trigger unauthorized data operations. Oracle classifies exploitation as easily achievable, requiring no user interaction. The impact covers confidentiality and integrity of all data accessible to Oracle Sales Offline, while availability is not affected. Given that Oracle E-Business Suite typically stores sales pipeline, customer, and account records, the exposure extends to business-critical enterprise data.

Root Cause

Oracle has not published detailed root-cause information for this vulnerability. Based on the CVSS metrics and impact description, the flaw stems from missing or improperly enforced authorization checks in the Internal Operations code path of Oracle Sales Offline. This allows a low-privileged principal to escalate their effective data access beyond what their role should permit.

Attack Vector

The attack is remote and requires only network reachability to the Oracle E-Business Suite HTTP interface. The attacker must hold valid low-privilege credentials, but no social engineering or victim interaction is needed. A single HTTP request sequence targeting the vulnerable Internal Operations endpoint is sufficient to reach the affected code path and manipulate accessible data.

No public proof-of-concept exploit is available at the time of writing. Refer to the Oracle Security Alert July 2026 for authoritative technical details.

Detection Methods for CVE-2026-60735

Indicators of Compromise

  • Unexpected create, update, or delete operations on Oracle Sales Offline records performed by low-privileged user accounts.
  • HTTP requests to Oracle E-Business Suite Internal Operations endpoints originating from accounts that do not normally access sales data.
  • Anomalous bulk data reads or exports from Oracle Sales Offline outside of documented business processes.

Detection Strategies

  • Correlate Oracle E-Business Suite application logs with authentication logs to flag privilege-inconsistent data operations.
  • Baseline normal HTTP request patterns to Oracle Sales Offline modules and alert on deviations, particularly on Internal Operations URLs.
  • Enable and review Oracle E-Business Suite auditing (FND_LOG_MESSAGES, page access tracking) for the affected version range 12.2.3-12.2.15.

Monitoring Recommendations

  • Forward Oracle E-Business Suite middle-tier and database audit logs to a centralized analytics platform for continuous review.
  • Monitor outbound data volumes from Oracle E-Business Suite servers to identify potential exfiltration following unauthorized reads.
  • Track patch state across all Oracle E-Business Suite instances to identify systems still exposed to CVE-2026-60735.

How to Mitigate CVE-2026-60735

Immediate Actions Required

  • Apply the July 2026 Critical Patch Update from Oracle to every Oracle E-Business Suite instance running Oracle Sales Offline versions 12.2.3 through 12.2.15.
  • Inventory Oracle E-Business Suite deployments and confirm patch status for the Oracle Sales Offline module specifically.
  • Review recent activity on Oracle Sales Offline for unauthorized data modification prior to patching.

Patch Information

Oracle released fixes for CVE-2026-60735 as part of the July 2026 Critical Patch Update. Administrators should follow Oracle's documented patching procedure for Oracle E-Business Suite 12.2.x. Full details are provided in the Oracle Security Alert July 2026.

Workarounds

  • Restrict network access to the Oracle E-Business Suite HTTP tier so only trusted internal networks and VPN users can reach it.
  • Enforce least-privilege on Oracle E-Business Suite responsibilities and remove Oracle Sales Offline access from users who do not require it.
  • Enable Oracle E-Business Suite Sign-On Audit and Page Access Tracking to increase visibility until patches are deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.