Description
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized read access to a subset of Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).
Published: 2026-07-21
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability permits a low‑privileged network attacker who can reach the Oracle Enterprise Command Center Framework over HTTP to bypass authorization controls and perform unauthorized actions. An attacker can create, delete, or modify critical data, read restricted subsets of data, and cause the application to hang or crash, leading to denial of service. The weakness combines an access‑control flaw (CWE‑284), a resource‑exhaustion vulnerability (CWE‑400), and potential SQL injection (CWE‑89). The impact includes low confidentiality loss, high integrity compromise, and high availability disruption, reflected in the CVSS 3.1 score of 8.3.

Affected Systems

The affected product is Oracle Corporation’s Enterprise Command Center Framework, version 16. No other versions or variants are known to be affected, and the issue is specific to this release. The product is part of Oracle E‑Business Suite and the description indicates that version v16 is impacted. There is no evidence suggesting that earlier or later releases are vulnerable.

Risk and Exploitability

The EPSS score is less than 1 % and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. The attack vector is network‑based HTTP; an attacker only needs network access to the framework on the specified version. Even so, the severity of the potential damage—unauthorized data manipulation, read access, and complete denial of service—makes the overall threat level high, emphasizing the need for prompt remediation.

Generated by OpenCVE AI on August 2, 2026 at 21:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the July 2026 CPU for Enterprise Command Center Framework v16.
  • Restrict HTTP access to the framework to trusted IP addresses or require VPN/strict firewall rules for authorized users.
  • Enable detailed audit logging for create, delete, modify, and crash events and monitor logs for anomalous activity.

Generated by OpenCVE AI on August 2, 2026 at 21:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Oracle Enterprise Command Center Framework Access‑Control Bypass with Data Loss and Denial of Service

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Access Control Bypass and Denial of Service in Oracle Enterprise Command Center Framework
Weaknesses CWE-770

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
CWE-89
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Low Privilege HTTP Access Control Bypass and Denial of Service in Oracle Enterprise Command Center Framework
Weaknesses CWE-284
CWE-770

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized read access to a subset of Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Command Center Framework
CPEs cpe:2.3:a:oracle:enterprise_command_center_framework:v16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Command Center Framework
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Oracle Enterprise Command Center Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:29:00.994Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60582

cve-icon Vulnrichment

Updated: 2026-07-27T12:28:53.316Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T22:00:07Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')