CVE-2026-60812 Overview
CVE-2026-60812 is an information disclosure vulnerability in the Oracle Supply Chain Trading Connector product within Oracle E-Business Suite. The flaw resides in the Collaboration History component and affects supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit this vulnerability without user interaction. Successful exploitation results in unauthorized access to critical data or complete access to all Oracle Supply Chain Trading Connector accessible data. The vulnerability was published to the National Vulnerability Database (NVD) on July 21, 2026, and disclosed as part of Oracle's July 2026 Critical Patch Update cycle.
Critical Impact
Authenticated attackers can retrieve sensitive trading partner and supply chain data over HTTP, exposing confidential business information to unauthorized users.
Affected Products
- Oracle E-Business Suite - Oracle Supply Chain Trading Connector 12.2.3
- Oracle E-Business Suite - Oracle Supply Chain Trading Connector versions 12.2.4 through 12.2.14
- Oracle E-Business Suite - Oracle Supply Chain Trading Connector 12.2.15
Discovery Timeline
- 2026-07-21 - CVE-2026-60812 published to NVD
- 2026-07-21 - Last updated in NVD database
- July 2026 - Oracle addresses the vulnerability in the Oracle Security Alert July 2026
Technical Details for CVE-2026-60812
Vulnerability Analysis
The vulnerability affects the Collaboration History component of Oracle Supply Chain Trading Connector, a module used to exchange trading documents and track collaboration events between supply chain partners. An authenticated attacker with low privileges can send crafted HTTP requests to the affected component and retrieve data they should not have access to. The attack requires no user interaction and no elevated permissions beyond standard application access.
The scope of exposure is confined to confidentiality. Integrity and availability are not affected, meaning attackers cannot modify records or disrupt service through this vector. However, the confidentiality impact is high because successful exploitation can yield complete access to all Oracle Supply Chain Trading Connector accessible data, including trading partner communications and collaboration histories.
The Exploit Prediction Scoring System (EPSS) reports a probability of 0.27% with a percentile of 18.944, indicating relatively low observed exploitation likelihood at publication.
Root Cause
Oracle has not published detailed root-cause information. Based on the advisory, the flaw appears to stem from insufficient authorization enforcement within the Collaboration History component, allowing low-privileged users to access data belonging to other tenants, partners, or accounts. Refer to the Oracle Security Alert July 2026 for vendor-specific remediation details.
Attack Vector
Exploitation requires network access via HTTP to the Oracle E-Business Suite instance hosting Supply Chain Trading Connector. The attacker must hold valid low-privileged credentials on the application. Once authenticated, the attacker sends crafted requests to endpoints exposed by the Collaboration History component to enumerate or retrieve unauthorized records. No client-side interaction or additional privilege escalation is required to trigger the disclosure.
Detection Methods for CVE-2026-60812
Indicators of Compromise
- Unusual volumes of HTTP requests to Collaboration History endpoints from a single authenticated session
- Authenticated user accounts accessing trading partner data outside their assigned scope or responsibility
- Anomalous data export or query patterns against Oracle Supply Chain Trading Connector tables
Detection Strategies
- Review Oracle E-Business Suite application audit logs for access to Collaboration History records by users lacking a documented business need
- Correlate HTTP access logs on the E-Business Suite web tier with application-layer identity to identify authorization anomalies
- Baseline normal query and page-access patterns for Supply Chain Trading Connector users and alert on statistical outliers
Monitoring Recommendations
- Enable and forward Oracle E-Business Suite audit logs and web server logs to a centralized SIEM for correlation
- Monitor privileged and low-privileged accounts equally, since exploitation only requires low privileges
- Track outbound data volumes from application servers to detect bulk data retrieval associated with Collaboration History queries
How to Mitigate CVE-2026-60812
Immediate Actions Required
- Apply the July 2026 Oracle Critical Patch Update to all Oracle E-Business Suite 12.2.3 through 12.2.15 instances running Supply Chain Trading Connector
- Inventory user accounts with access to Supply Chain Trading Connector and remove any that are not required
- Review recent access logs for the Collaboration History component to identify potentially exposed data prior to patching
Patch Information
Oracle addressed CVE-2026-60812 in the July 2026 Critical Patch Update. Patch downloads and installation guidance are available through the Oracle Security Alert July 2026. Administrators should follow Oracle's documented E-Business Suite patching procedures and validate the patch in a non-production environment before rollout.
Workarounds
- Restrict network access to the E-Business Suite HTTP endpoints so that only trusted internal networks or VPN users can reach Supply Chain Trading Connector
- Reduce the number of accounts with any level of access to Supply Chain Trading Connector until patches are applied
- Enforce web application firewall (WAF) rules that rate-limit and log access to Collaboration History URLs
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

