Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60812

CVE-2026-60812: Oracle E-Business Suite Data Disclosure

CVE-2026-60812 is an information disclosure vulnerability in Oracle Supply Chain Trading Connector that allows unauthorized access to critical data. This article covers the technical details, affected versions, and mitigation.

Published:

CVE-2026-60812 Overview

CVE-2026-60812 is an information disclosure vulnerability in the Oracle Supply Chain Trading Connector product within Oracle E-Business Suite. The flaw resides in the Collaboration History component and affects supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit this vulnerability without user interaction. Successful exploitation results in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data. The vulnerability was published to the National Vulnerability Database (NVD) on July 21, 2026, and disclosed as part of Oracle's July 2026 Critical Patch Update cycle.

Critical Impact

Authenticated attackers can retrieve sensitive trading partner and supply chain data over HTTP, exposing confidential business information to unauthorized users.

Affected Products

  • Oracle E-Business Suite - Oracle Supply Chain Trading Connector 12.2.3
  • Oracle E-Business Suite - Oracle Supply Chain Trading Connector versions 12.2.4 through 12.2.14
  • Oracle E-Business Suite - Oracle Supply Chain Trading Connector 12.2.15

Discovery Timeline

  • 2026-07-21 - CVE-2026-60812 published to NVD
  • 2026-07-21 - Last updated in NVD database
  • July 2026 - Oracle addresses the vulnerability in the Oracle Security Alert July 2026

Technical Details for CVE-2026-60812

Vulnerability Analysis

The vulnerability affects the Collaboration History component of Oracle Supply Chain Trading Connector, a module used to exchange trading documents and track collaboration events between supply chain partners. An authenticated attacker with low privileges can send crafted HTTP requests to the affected component and retrieve data they should not have access to. The attack requires no user interaction and no elevated permissions beyond standard application access.

The scope of exposure is confined to confidentiality. Integrity and availability are not affected, meaning attackers cannot modify records or disrupt service through this vector. However, the confidentiality impact is high because successful exploitation can yield complete access to all Oracle Supply Chain Trading Connector accessible data, including trading partner communications and collaboration histories.

The Exploit Prediction Scoring System (EPSS) reports a probability of 0.27% with a percentile of 18.944, indicating relatively low observed exploitation likelihood at publication.

Root Cause

Oracle has not published detailed root-cause information. Based on the advisory, the flaw appears to stem from insufficient authorization enforcement within the Collaboration History component, allowing low-privileged users to access data belonging to other tenants, partners, or accounts. Refer to the Oracle Security Alert July 2026 for vendor-specific remediation details.

Attack Vector

Exploitation requires network access via HTTP to the Oracle E-Business Suite instance hosting Supply Chain Trading Connector. The attacker must hold valid low-privileged credentials on the application. Once authenticated, the attacker sends crafted requests to endpoints exposed by the Collaboration History component to enumerate or retrieve unauthorized records. No client-side interaction or additional privilege escalation is required to trigger the disclosure.

Detection Methods for CVE-2026-60812

Indicators of Compromise

  • Unusual volumes of HTTP requests to Collaboration History endpoints from a single authenticated session
  • Authenticated user accounts accessing trading partner data outside their assigned scope or responsibility
  • Anomalous data export or query patterns against Oracle Supply Chain Trading Connector tables

Detection Strategies

  • Review Oracle E-Business Suite application audit logs for access to Collaboration History records by users lacking a documented business need
  • Correlate HTTP access logs on the E-Business Suite web tier with application-layer identity to identify authorization anomalies
  • Baseline normal query and page-access patterns for Supply Chain Trading Connector users and alert on statistical outliers

Monitoring Recommendations

  • Enable and forward Oracle E-Business Suite audit logs and web server logs to a centralized SIEM for correlation
  • Monitor privileged and low-privileged accounts equally, since exploitation only requires low privileges
  • Track outbound data volumes from application servers to detect bulk data retrieval associated with Collaboration History queries

How to Mitigate CVE-2026-60812

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to all Oracle E-Business Suite 12.2.3 through 12.2.15 instances running Supply Chain Trading Connector
  • Inventory user accounts with access to Supply Chain Trading Connector and remove any that are not required
  • Review recent access logs for the Collaboration History component to identify potentially exposed data prior to patching

Patch Information

Oracle addressed CVE-2026-60812 in the July 2026 Critical Patch Update. Patch downloads and installation guidance are available through the Oracle Security Alert July 2026. Administrators should follow Oracle's documented E-Business Suite patching procedures and validate the patch in a non-production environment before rollout.

Workarounds

  • Restrict network access to the E-Business Suite HTTP endpoints so that only trusted internal networks or VPN users can reach Supply Chain Trading Connector
  • Reduce the number of accounts with any level of access to Supply Chain Trading Connector until patches are applied
  • Enforce web application firewall (WAF) rules that rate-limit and log access to Collaboration History URLs

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.