Description
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Financials Common Modules allows an attacker with only low‑privilege network access over HTTP to create, delete, or modify critical data. The weakness is an authorization bypass (CWE‑284) where the system fails to enforce proper privilege checks, enabling unauthorized manipulation of or access to all module data.

Affected Systems

Oracle Corporation’s Oracle Financials Common Modules, supported versions 12.2.3 through 12.2.15, are affected. The vulnerability resides in the Common Components component of the Oracle E‑Business Suite.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a low current exploitation probability. The flaw is not listed in the CISA KEV catalog. An attacker can exploit the vulnerability over the network via HTTP with only low-level privileges, enabling potential wide‑scale data compromise if not mitigated.

Generated by OpenCVE AI on August 4, 2026 at 02:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the July 2026 CPU that addresses this flaw.
  • Limit HTTP exposure to the Financials Common Modules by restricting access to trusted IP ranges or internal networks.
  • Enforce strict role‑based access controls so that only privileged users can perform create, delete, or modify operations.
  • Disable or remove legacy or unnecessary user accounts with lower privileges that have access to the affected modules.

Generated by OpenCVE AI on August 4, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Oracle Financials Common Modules Authorization Bypass Allows Unauthorized Data Modification

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Oracle Financials Common Modules Authorization Bypass Allows Unauthorized Data Modification

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Financials Common Modules via HTTP

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Financials Common Modules via HTTP
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle financials Common Modules
CPEs cpe:2.3:a:oracle:financials_common_modules:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle financials Common Modules
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle E-business Suite Financials Common Modules
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:22:11.292Z

Reserved: 2026-07-08T15:51:55.588Z

Link: CVE-2026-60764

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:27.577Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:15.840

Modified: 2026-08-07T21:00:50.483

Link: CVE-2026-60764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:00:02Z

Weaknesses