Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60844

CVE-2026-60844: Oracle E-Business Suite Auth Bypass Flaw

CVE-2026-60844 is an authentication bypass vulnerability in Oracle E-Business Suite Customer Support that allows unauthorized data access and modification. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-60844 Overview

CVE-2026-60844 is a high-severity vulnerability in the Oracle Customer Support product of Oracle E-Business Suite. The flaw resides in the Update Service Request component and affects supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access over HTTP can exploit this issue to compromise Oracle Customer Support. Successful exploitation permits unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all Oracle Customer Support accessible data. Oracle addressed the vulnerability in the July 2026 Critical Patch Update.

Critical Impact

Authenticated attackers can read, modify, or destroy all data accessible to Oracle Customer Support through network-based HTTP requests.

Affected Products

  • Oracle E-Business Suite 12.2.3 through 12.2.15
  • Oracle Customer Support product (Update Service Request component)
  • Deployments exposing the Oracle E-Business Suite web tier over HTTP

Discovery Timeline

Technical Details for CVE-2026-60844

Vulnerability Analysis

The vulnerability affects the Update Service Request component of Oracle Customer Support within Oracle E-Business Suite. An attacker holding low-privileged application credentials can send crafted HTTP requests to the affected endpoint. The service processes these requests without adequately enforcing authorization on the targeted service request records. As a result, the attacker gains read and write access beyond the scope permitted for their account. Oracle categorizes the impact as high for both confidentiality and integrity, with no direct availability impact.

Root Cause

Oracle has not published the underlying weakness class, and no CWE identifier is assigned in the NVD entry. Based on the impact profile and low privilege requirement, the flaw is consistent with broken access control on the Update Service Request handler. The component appears to accept authenticated input that references arbitrary service request objects without validating that the caller owns or is authorized to modify the referenced records.

Attack Vector

Exploitation requires network reachability to the Oracle E-Business Suite HTTP interface and a valid low-privileged account. The attack complexity is low and no user interaction is required. An attacker sends authenticated HTTP requests to the Update Service Request functionality, targeting record identifiers or parameters that the application fails to authorize correctly. Successful requests return or alter Customer Support data outside the attacker's normal scope. No public proof-of-concept, exploit code, or CISA KEV listing exists at the time of publication. The EPSS score is 0.365% (29th percentile), reflecting low observed exploitation activity to date.

No verified exploit code is available. See the Oracle Security Advisory July 2026 for vendor technical details.

Detection Methods for CVE-2026-60844

Indicators of Compromise

  • Unexpected modifications, creations, or deletions of service request records in Oracle Customer Support audit tables
  • Authenticated HTTP requests to Update Service Request endpoints from accounts that do not normally interact with those records
  • Bulk enumeration of service request identifiers by a single low-privileged application user

Detection Strategies

  • Enable and review Oracle E-Business Suite Sign-On Audit and Page Access Tracking for the Customer Support module
  • Correlate application-tier logs with database audit records to identify unauthorized data changes tied to Update Service Request actions
  • Baseline normal Update Service Request activity per user role and alert on deviations in volume or targeted record ranges

Monitoring Recommendations

  • Forward Oracle E-Business Suite application, web tier, and database audit logs to a centralized SIEM for correlation
  • Monitor HTTP access logs on the Oracle HTTP Server for anomalous request patterns to OA.jsp and Customer Support form functions
  • Alert on privilege changes, role grants, or responsibility assignments involving Oracle Customer Support during the exposure window

How to Mitigate CVE-2026-60844

Immediate Actions Required

  • Apply the July 2026 Oracle Critical Patch Update to all Oracle E-Business Suite 12.2.3 through 12.2.15 environments
  • Inventory all Oracle E-Business Suite deployments and confirm patch level after installation
  • Review recent Customer Support activity for unauthorized service request modifications during the exposure window
  • Rotate credentials for any low-privileged application accounts suspected of misuse

Patch Information

Oracle released the fix as part of the July 2026 Critical Patch Update. Administrators should follow the vendor guidance in the Oracle Critical Patch Update Advisory - July 2026 and apply the appropriate patch for the installed Oracle E-Business Suite 12.2 release level. Restart the application and web tiers after patching to ensure updated components are loaded.

Workarounds

  • Restrict network access to the Oracle E-Business Suite HTTP interface to trusted internal networks and VPN clients until patches are applied
  • Limit assignment of Oracle Customer Support responsibilities to users with documented business need
  • Enforce strong authentication and monitor low-privileged accounts with access to Customer Support functions

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.