CVE-2026-60940 Overview
CVE-2026-60940 is a vulnerability in the Oracle Service Contracts product of Oracle E-Business Suite, within the Internal Operations component. The flaw affects supported versions 12.2.3 through 12.2.15. A high-privileged attacker with network access over HTTP can compromise Oracle Service Contracts, but successful exploitation requires human interaction from a user other than the attacker. The vulnerability is difficult to exploit and does not impact availability.
Critical Impact
Successful attacks can result in unauthorized creation, deletion, or modification of critical Oracle Service Contracts data, as well as full read access to all data accessible through Oracle Service Contracts.
Affected Products
- Oracle E-Business Suite - Oracle Service Contracts version 12.2.3
- Oracle E-Business Suite - Oracle Service Contracts versions 12.2.4 through 12.2.14
- Oracle E-Business Suite - Oracle Service Contracts version 12.2.15
Discovery Timeline
- 2026-07-21 - CVE CVE-2026-60940 published to NVD as part of Oracle's July 2026 Critical Patch Update
- 2026-07-21 - Last updated in NVD database
Technical Details for CVE-2026-60940
Vulnerability Analysis
The vulnerability resides in the Internal Operations component of Oracle Service Contracts, an Oracle E-Business Suite module used to manage service agreements, warranties, and subscription contracts. The flaw allows an authenticated attacker holding high privileges to abuse HTTP-facing functionality to alter or extract data managed by the Service Contracts application.
Oracle categorizes the impact as high on confidentiality and integrity, with no impact on availability. The attacker must first obtain elevated application-level access, then trick a legitimate user into performing an action that triggers the vulnerable code path. This human interaction requirement, combined with the high attack complexity, reduces the likelihood of opportunistic exploitation. The EPSS probability for CVE-2026-60940 is 0.269%, placing it in the 18.8th percentile of predicted exploit likelihood.
Root Cause
Oracle has not published detailed root-cause information. Based on the advisory metadata, the vulnerability requires an authenticated privileged session and a secondary user action, which is consistent with input validation or access control weaknesses reachable through the Service Contracts HTTP interface. Refer to the Oracle Security Advisory July 2026 for vendor-provided technical details.
Attack Vector
Exploitation occurs over the network via HTTP against an Oracle E-Business Suite deployment exposing Oracle Service Contracts. The attacker must be authenticated with high privileges within the application. A second user must then perform an action, such as loading a crafted page or interacting with a manipulated contract record, for the attack chain to complete. The scope is unchanged, meaning impact is contained to the Oracle Service Contracts application context.
No public proof-of-concept, exploit code, or CISA KEV listing exists for CVE-2026-60940 at the time of publication.
Detection Methods for CVE-2026-60940
Indicators of Compromise
- Unexpected creation, modification, or deletion of Service Contracts records by privileged accounts outside of documented change windows.
- Anomalous HTTP requests to Oracle Service Contracts Internal Operations endpoints originating from unusual client sessions or IP addresses.
- Privileged application accounts initiating actions that immediately precede unexpected interactive user activity on the same contract objects.
Detection Strategies
- Enable and review Oracle E-Business Suite auditing (FND_LOG_MESSAGES, sign-on audit, and page access tracking) for Service Contracts modules.
- Correlate application-tier HTTP access logs with database DML operations against OKS_* and OKC_* schema tables to identify unauthorized data changes.
- Baseline the normal volume and pattern of privileged Service Contracts operations and alert on deviations.
Monitoring Recommendations
- Forward Oracle E-Business Suite application, middle-tier, and database audit logs to a centralized SIEM for cross-correlation.
- Monitor for privilege changes and role grants that would enable an actor to reach the high-privilege prerequisite of this vulnerability.
- Track outbound data volumes from Service Contracts sessions to identify bulk read activity consistent with unauthorized data access.
How to Mitigate CVE-2026-60940
Immediate Actions Required
- Apply the Oracle Critical Patch Update released in July 2026 to all affected Oracle E-Business Suite environments running Service Contracts versions 12.2.3 through 12.2.15.
- Inventory all E-Business Suite instances and confirm patch level for the Service Contracts module before returning systems to production use.
- Review and reduce the population of accounts with high privileges in Oracle Service Contracts to shrink the attack surface.
Patch Information
Oracle addressed CVE-2026-60940 in the July 2026 Critical Patch Update. Administrators should download and apply the fix as documented in the Oracle Security Advisory July 2026. Oracle strongly recommends applying Critical Patch Update fixes as soon as possible, since Oracle does not provide additional information about the specific technical details of vulnerabilities.
Workarounds
- Restrict network access to Oracle E-Business Suite HTTP endpoints to trusted internal networks and VPN clients only.
- Enforce strong session controls and multi-factor authentication for privileged Oracle E-Business Suite users to make prerequisite privilege abuse harder.
- Provide targeted user awareness guidance so that Service Contracts users recognize and report unexpected prompts or interactions that could constitute the required human interaction step.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

