Description
Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in takeover of Oracle iReceivables. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the AR Web Utilities component of Oracle iReceivables allows an unauthenticated attacker to compromise the application, potentially taking full control and affecting confidentiality, integrity, and availability. The high CVSS score of 8.1 indicates severe impact.

Affected Systems

Oracle iReceivables, part of Oracle E‑Business Suite, is affected for supported versions 12.2.3 through 12.2.15. The issue targets the AR Web Utilities component within this product range.

Risk and Exploitability

The CVSS score of 8.1 denotes severe impact, while the EPSS score of less than 1 % signals that exploitation in the wild is currently uncommon. Because the flaw is accessed over the network, an attacker only needs connectivity to the AR Web Utilities HTTP interface; the pathway requires high attack complexity and no user interaction, yet once leveraged it can lead to a complete takeover. The vulnerability is not listed in the CISA KEV catalog, indicating no documented widespread exploitation.

Generated by OpenCVE AI on August 4, 2026 at 16:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle E‑Business Suite patch that fixes CVE‑2026‑60785 and upgrade to a non‑affected version if available.
  • Restrict HTTP access to the AR Web Utilities component to trusted IP addresses and enforce authentication, or place it behind a firewall or VPN.
  • If a patch cannot be applied immediately, consider disabling the AR Web Utilities interface for public traffic and monitor logs for suspicious activity.

Generated by OpenCVE AI on August 4, 2026 at 16:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Takeover of Oracle iReceivables
Weaknesses CWE-284

Tue, 04 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Takeover in Oracle iReceivables AR Web Utilities
Weaknesses CWE-284

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Takeover in Oracle iReceivables AR Web Utilities
Weaknesses CWE-284

Mon, 27 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access to Oracle iReceivables
Weaknesses CWE-284

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Access to Oracle iReceivables
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iReceivables product of Oracle E-Business Suite (component: AR Web Utilities). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iReceivables. Successful attacks of this vulnerability can result in takeover of Oracle iReceivables. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle ireceivables
CPEs cpe:2.3:a:oracle:ireceivables:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle ireceivables
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Ireceivables
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:20:50.871Z

Reserved: 2026-07-08T15:51:55.590Z

Link: CVE-2026-60785

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:17.500

Modified: 2026-07-29T15:03:10.943

Link: CVE-2026-60785

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses