Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60912

CVE-2026-60912: Oracle Property Manager Auth Bypass Flaw

CVE-2026-60912 is an authentication bypass vulnerability in Oracle Property Manager that allows low-privileged attackers to gain unauthorized access to data. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-60912 Overview

CVE-2026-60912 is a vulnerability in the Oracle Property Manager product of Oracle E-Business Suite, specifically in the Internal Operations component. The flaw affects supported versions 12.2.3 through 12.2.15. A low-privileged attacker with network access via HTTP can exploit this weakness to compromise Oracle Property Manager. Successful exploitation grants unauthorized update, insert, or delete access to a subset of Property Manager data, along with unauthorized read access to a subset of the accessible data. Oracle disclosed the issue as part of the July 2026 Critical Patch Update.

Critical Impact

Authenticated attackers can modify and read a subset of Property Manager data over the network, affecting the integrity and confidentiality of Oracle E-Business Suite tenant records.

Affected Products

  • Oracle E-Business Suite — Oracle Property Manager 12.2.3
  • Oracle E-Business Suite — Oracle Property Manager versions 12.2.4 through 12.2.14
  • Oracle E-Business Suite — Oracle Property Manager 12.2.15

Discovery Timeline

Technical Details for CVE-2026-60912

Vulnerability Analysis

The vulnerability resides in the Internal Operations component of Oracle Property Manager, part of the Oracle E-Business Suite (EBS) application stack. Oracle classifies the flaw as easily exploitable over HTTP by an attacker holding a low-privileged account on the target EBS instance. Exploitation does not require user interaction, and the attacker's actions remain within the vulnerable component's security scope.

Successful attacks compromise both the integrity and confidentiality of Property Manager data. Attackers can perform unauthorized insert, update, or delete operations against a subset of the module's accessible records. They can also read a subset of accessible data without authorization. Availability of the application is not directly impacted.

The EPSS score for CVE-2026-60912 currently stands at 0.251%, reflecting a low observed likelihood of exploitation attempts in the near term. Organizations should still treat the flaw seriously because EBS deployments frequently host sensitive lease, tenant, and financial records.

Root Cause

Oracle has not published the underlying code-level defect. Based on the CVSS profile and impact statement, the flaw stems from insufficient authorization enforcement in the Internal Operations component, allowing a low-privileged authenticated user to perform data operations that should be restricted to higher-privileged roles.

Attack Vector

The attack vector is network-based over HTTP against the Oracle E-Business Suite web tier. The attacker must possess a valid, low-privileged EBS account. Once authenticated, the attacker issues crafted HTTP requests to Property Manager endpoints tied to Internal Operations to read or manipulate records beyond their authorization boundary.

No verified public proof-of-concept code is available for CVE-2026-60912 at this time. Technical details are described here in prose; see the Oracle Critical Patch Update - July 2026 for vendor-supplied context.

Detection Methods for CVE-2026-60912

Indicators of Compromise

  • Unexpected INSERT, UPDATE, or DELETE operations against Property Manager tables initiated by low-privileged EBS user accounts.
  • HTTP requests to Property Manager Internal Operations URLs from user sessions that historically do not access this module.
  • Audit log entries showing Property Manager data changes outside of scheduled business processes or approved change windows.

Detection Strategies

  • Enable and review Oracle EBS Sign-On Audit and Page Access Tracking for Property Manager responsibilities.
  • Correlate database-level auditing on Property Manager schema objects with application-layer user identities.
  • Baseline normal Property Manager usage per user role and alert on deviations, particularly write operations by read-only or limited roles.

Monitoring Recommendations

  • Forward Oracle EBS application, middle-tier, and database audit logs to a centralized SIEM for continuous analysis.
  • Monitor Oracle HTTP Server access logs for anomalous request patterns targeting Property Manager URIs.
  • Track privilege assignments and responsibility grants in EBS to detect unauthorized elevation attempts that could pair with this flaw.

How to Mitigate CVE-2026-60912

Immediate Actions Required

  • Apply the fixes delivered in the Oracle Critical Patch Update - July 2026 to all Oracle E-Business Suite instances running Property Manager versions 12.2.3 through 12.2.15.
  • Inventory all EBS environments, including development and test tiers, to ensure no vulnerable Property Manager deployment is missed.
  • Review and tighten Property Manager responsibility and role assignments to limit low-privileged account exposure.

Patch Information

Oracle addresses CVE-2026-60912 in the July 2026 Critical Patch Update. Administrators should download and apply the recommended patches for Oracle E-Business Suite 12.2 as documented in the advisory. Follow Oracle's standard EBS patching process, including AutoConfig and any post-patch steps required for the Property Manager module.

Workarounds

  • Restrict network access to the EBS web tier so that only trusted internal networks and VPN clients can reach Property Manager endpoints.
  • Disable or restrict Property Manager responsibilities for users who do not require the module, reducing the pool of accounts that could exploit the flaw.
  • Increase audit logging on Property Manager schema objects until the patch is applied so that any exploitation attempts leave a clear forensic trail.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.