Description
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-07-21
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Application Object Library for Oracle E‑Business Suite contains a flaw that allows a low‑privilege attacker with network access over HTTPS to gain higher privileges and then create, delete, or modify critical data. The vulnerability also grants an attacker unauthorized access to all data that the library exposes, and the flaw changes attack scope, potentially affecting additional components. This Access Control (CWE‑284) flaw is measured by a CVSS 3.1 score of 9.6, indicating a high confidential‑and‑integrity impact.

Affected Systems

Oracle Application Object Library, Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The high CVSS score and the fact that HTTPS means that any user with low privilege who can reach the exposed service could exploit the flaw. The EPSS score is so current exploitation activity is low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the scope‑changing nature of the vulnerability provides the potential for significant impact beyond the immediate component.

Generated by OpenCVE AI on August 2, 2026 at 21:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Oracle’s security update site for a patch that addresses CVE‑2026‑60773 and apply it as soon as it is available.
  • Use firewalls and VPN controls to limit HTTPS connections to the Oracle Application Object Library to trusted internal hosts only, and consider enabling client‑side TLS authentication to further restrict access.
  • Audit user roles and privileges in the application to enforce least privilege; remove any unnecessary rights that could facilitate unauthorized data creation, deletion, or modification.

Generated by OpenCVE AI on August 2, 2026 at 21:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege Escalation and Unauthorized Data Access in Oracle Application Object Library

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Access Control Exploit Enables Unauthorized Data Modification in Oracle Application Object Library

Sun, 26 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Access Control Exploit Enables Unauthorized Data Modification in Oracle Application Object Library

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Application Object Library. While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle application Object Library
CPEs cpe:2.3:a:oracle:application_object_library:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle application Object Library
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Application Object Library
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-01T03:56:25.095Z

Reserved: 2026-07-08T15:51:55.589Z

Link: CVE-2026-60773

cve-icon Vulnrichment

Updated: 2026-07-24T19:04:02.784Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:16.443

Modified: 2026-08-07T21:23:02.450

Link: CVE-2026-60773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:15:02Z

Weaknesses