Description
Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform). Supported versions that are affected are 26.0.0, 26.1.0 and 26.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides within the Developer triaging platform of Oracle Autonomous Health Framework and permits a local, high-privileged attacker who is logged into the host infrastructure to compromise the entire framework. Successful exploitation requires human interaction from a user other than the attacker, an element explicitly noted in the description. Once exploited, the attacker obtains full control of the framework, achieving confidentiality, integrity, and availability impact, as reflected by the CVSS vector (AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H) and the referenced CWE-284.

Affected Systems

Oracle Autonomous Health Framework versions 26.0.0, 26.1.0, and 26.2.0 are affected. The flaw is specific to the Developer triaging platform component within these releases.

Risk and Exploitability

The EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS base score of 6.3 reflects moderate severity, yet the potential impact is high because of the complete takeover capability. Exploitation requires local high-privilege access and an additional human interaction, limiting automated attacks but still posing a significant threat where privileged users have access to the host environment.

Generated by OpenCVE AI on August 4, 2026 at 04:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Autonomous Health Framework to any version later than 26.2.0 that contains the vendor’s fix.
  • Restrict local high-privilege access to the host that runs the framework by enforcing strict role-based access controls and isolating the Developer triaging platform from users with elevated privileges.
  • Apply standard access-control hardening to mitigate the CWE-284 weakness, ensuring that only authorized personnel can perform developer-triaging functions and that all actions require authenticated, privileged, and audited access.

Generated by OpenCVE AI on August 4, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Autonomous Health Framework Developer Triaging Platform

Thu, 30 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Privileged Local Exploit Enables Full Takeover of Oracle Autonomous Health Framework

Fri, 24 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Privileged Local Exploit Enables Full Takeover of Oracle Autonomous Health Framework

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform). Supported versions that are affected are 26.0.0, 26.1.0 and 26.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle autonomous Health Framework
CPEs cpe:2.3:a:oracle:autonomous_health_framework:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.2.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle autonomous Health Framework
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Autonomous Health Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T16:21:28.641Z

Reserved: 2026-07-08T15:51:40.517Z

Link: CVE-2026-60172

cve-icon Vulnrichment

Updated: 2026-07-23T16:21:21.169Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:00:05Z

Weaknesses