Description
Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Field Service accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a flaw in Oracle Field Service’s Internal Operations component that permits improper access control (CWE‑284). A remote attacker who can reach the service over HTTP, without needing privileged credentials, can read sensitive data and perform unauthorized insert, update or delete operations. The impact on confidentiality is high and on integrity is moderate, with no effect on availability.

Affected Systems

Oracle Field Service, part of Oracle E‑Business Suite, is affected in versions 12.2.3 through 12.2.15. The issue resides in the Operations component of the product.

Risk and Exploitability

The CVSS v3.1 score of 7.1 indicates a significant threat to confidentiality and a moderate risk to integrity. Attackers require only network access to an exposed HTTP endpoint and have no privilege escalation requirement. The EPSS score is below 1 % and the flaw is not listed in the CISA KEV catalog, suggesting a currently low probability of exploitation but indicating that passive exposure should be mitigated immediately because of the high potential damage.

Generated by OpenCVE AI on August 2, 2026 at 21:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑issued security patch that addresses CVE‑2026‑60739.
  • Configure firewall or reverse‑proxy rules to restrict inbound HTTP traffic to Oracle Field Service from trusted IP ranges.
  • Apply the principle of least privilege to user accounts interacting with Oracle Field Service, ensuring they have only the minimum rights required.
  • Enable comprehensive logging of data access and regularly audit logs to detect unauthorized activity.

Generated by OpenCVE AI on August 2, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via HTTP in Oracle Field Service

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Network Data Access in Oracle Field Service via HTTP

Mon, 27 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Network Data Access in Oracle Field Service via HTTP

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as unauthorized update, insert or delete access to some of Oracle Field Service accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle field Service
CPEs cpe:2.3:a:oracle:field_service:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle field Service
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Field Service
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:23:12.820Z

Reserved: 2026-07-08T15:51:55.585Z

Link: CVE-2026-60739

cve-icon Vulnrichment

Updated: 2026-07-24T15:15:18.213Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:14.347

Modified: 2026-08-03T16:34:37.660

Link: CVE-2026-60739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses