Description
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Enterprise Command Center Framework version 16 contains a flaw that permits an unauthenticated attacker who can reach the physical communication segment attached to the hardware to take control of the framework. This vulnerability is a CWE‑284 Access Control weakness that, once exploited, results in a takeover of the framework, defeating confidentiality, integrity, and availability of the entire system.

Affected Systems

Oracle Enterprise Command Center Framework, part of Oracle E‑Business Suite, version 16. The affected component is the core framework of the product, under the Oracle brand. No other vendors or product versions are documented as affected.

Risk and Exploitability

The likely attack vector requires access to the physical communication segment of the hardware; this is an inferred local network path based on the description. The vulnerability carries a CVSS 3.1 base score of 7.5, indicating moderate to high severity with full confidentiality, integrity, and availability impacts. The EPSS score is less than 1%, suggesting a low current exploitation probability, and the issue is not listed in the CISA KEV catalog. Although exploitation conditions are restrictive, the potential for a complete compromise warrants attention for systems exposed to such access.

Generated by OpenCVE AI on August 5, 2026 at 02:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for Enterprise Command Center Framework v16 as described in the official advisory
  • Secure the physical communication segment by restricting access to authorized personnel only
  • Monitor local network traffic for anomalous activity that could indicate exploitation attempts

Generated by OpenCVE AI on August 5, 2026 at 02:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Network Attack Compromises Oracle Enterprise Command Center Framework v16

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Network Attack Compromises Oracle Enterprise Command Center Framework v16

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access Allows Full Compromise of Oracle Enterprise Command Center Framework
Weaknesses CWE-862

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Local Access Allows Full Compromise of Oracle Enterprise Command Center Framework
Weaknesses CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Enterprise Command Center Framework executes to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Command Center Framework
CPEs cpe:2.3:a:oracle:enterprise_command_center_framework:v16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Command Center Framework
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Command Center Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:28:18.329Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60581

cve-icon Vulnrichment

Updated: 2026-07-27T12:28:14.635Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:58.480

Modified: 2026-08-04T20:28:27.560

Link: CVE-2026-60581

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:30:03Z

Weaknesses