Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60864

CVE-2026-60864: Oracle Order Management SQLi Vulnerability

CVE-2026-60864 is a SQL injection vulnerability in Oracle Order Management that enables unauthorized data access and modification. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-60864 Overview

CVE-2026-60864 affects the Oracle Order Management product within Oracle E-Business Suite, specifically the Product Diagnostic Tools component. The flaw exists in supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit this vulnerability without user interaction. Although the flaw resides in Oracle Order Management, successful exploitation triggers a scope change and can impact additional products. Attackers can gain unauthorized update, insert, or delete access to some Oracle Order Management data, plus unauthorized read access to a subset of that data.

Critical Impact

Authenticated attackers over the network can modify and read Oracle Order Management data, with scope change extending impact to additional Oracle E-Business Suite components.

Affected Products

  • Oracle E-Business Suite - Oracle Order Management 12.2.3
  • Oracle E-Business Suite - Oracle Order Management versions 12.2.4 through 12.2.14
  • Oracle E-Business Suite - Oracle Order Management 12.2.15

Discovery Timeline

Technical Details for CVE-2026-60864

Vulnerability Analysis

The vulnerability resides in the Product Diagnostic Tools component of Oracle Order Management, part of the Oracle E-Business Suite platform. An authenticated attacker with low privileges can send crafted HTTP requests to reach the affected functionality. The Product Diagnostic Tools component processes these requests in a way that allows unauthorized data manipulation and disclosure.

Exploitation is described by Oracle as easy, requiring no user interaction. The scope change indicates that a successful attack can affect resources beyond the vulnerable component's security authority. This behavior is characteristic of shared-session or shared-database access patterns common in Oracle E-Business Suite deployments.

The EPSS score is 0.24% (15.2 percentile), indicating a low current probability of exploitation activity. However, Oracle E-Business Suite deployments frequently host critical business data, elevating the practical risk.

Root Cause

Oracle has not published detailed root cause information beyond the July 2026 Critical Patch Update advisory. The behavior — low-privilege network exploitation leading to cross-scope data modification — is consistent with a broken access control or missing authorization check within the Product Diagnostic Tools endpoints. No CWE identifier has been assigned in the NVD entry.

Attack Vector

The attack vector is network-based over HTTP. An attacker must hold valid low-privileged credentials on the target Oracle E-Business Suite instance. From that authenticated position, the attacker sends HTTP requests to Product Diagnostic Tools endpoints to trigger unauthorized reads, inserts, updates, or deletes against Oracle Order Management data. Because of the scope change, downstream Oracle E-Business Suite products sharing data or trust boundaries with Order Management can also be affected.

No public proof-of-concept exploit is available at this time. Details of the vulnerable requests are described in the Oracle Security Alert July 2026.

Detection Methods for CVE-2026-60864

Indicators of Compromise

  • Unexpected HTTP requests from authenticated low-privileged users targeting Product Diagnostic Tools URLs within Oracle E-Business Suite.
  • Unauthorized modifications, insertions, or deletions in Oracle Order Management tables not tied to standard business workflows.
  • Anomalous read queries against Order Management data originating from accounts without a business need.

Detection Strategies

  • Enable and review Oracle E-Business Suite Sign-On Audit and Page Access Tracking to identify unusual access to Product Diagnostic Tools functions.
  • Correlate HTTP access logs from Oracle HTTP Server with database audit trails to detect low-privileged accounts performing write operations on Order Management data.
  • Baseline normal user access patterns for the Product Diagnostic Tools component and alert on deviations.

Monitoring Recommendations

  • Forward Oracle E-Business Suite application logs, Oracle HTTP Server logs, and database audit logs to a centralized SIEM for correlation.
  • Alert on Order Management DML operations originating from responsibilities not authorized to perform such changes.
  • Monitor for privilege changes and new responsibility assignments on Oracle E-Business Suite user accounts.

How to Mitigate CVE-2026-60864

Immediate Actions Required

  • Apply the Oracle Critical Patch Update from July 2026 to all Oracle E-Business Suite 12.2.3 through 12.2.15 instances.
  • Inventory all Oracle E-Business Suite environments to confirm patch coverage across production, test, and development tiers.
  • Review Oracle E-Business Suite user responsibilities and revoke access to Product Diagnostic Tools for accounts that do not require it.

Patch Information

Oracle addressed this vulnerability in the July 2026 Critical Patch Update. Administrators should reference the Oracle Security Alert July 2026 for the specific patch identifiers and installation instructions applicable to their Oracle E-Business Suite version. Apply patches through Oracle's standard AutoPatch (adop) process for 12.2 environments.

Workarounds

  • Restrict network access to Oracle E-Business Suite HTTP endpoints using firewall rules or reverse proxy allow-lists until patches are applied.
  • Disable or restrict access to Product Diagnostic Tools responsibilities where operationally feasible.
  • Enforce least privilege on all Oracle E-Business Suite accounts and remove unused low-privileged accounts that could be leveraged by an attacker.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.