Description
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CVE-2026-60826 describes an access‑control flaw, identified as CWE‑284, in Oracle iSupport’s Internal Operations component that allows a high‑privileged attacker with HTTP network access to compromise the application. The vulnerability, classified as medium severity with a CVSS 3.1 Base Score of 6.6, can lead to full system takeover, exposing confidential data and disrupting integrity and availability. The vector indicates that a successful exploit requires an attacker with high‑level privileges and access to the iSupport HTTP endpoints.

Affected Systems

The affected product is Oracle iSupport, part of Oracle E‑Business Suite. Oracle Corporation’s iSupport component is impacted in supported releases 12.2.3 through 12.2.15. No further version detail is disclosed beyond the nominal range in the public advisory.

Risk and Exploitability

The CVSS score of 6.6 places the issue in the medium severity band, yet the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating that no confirmed exploits have been reported. An attacker would typically target the iSupport HTTP endpoints and must already possess high privileges or a privileged foothold before the flaw can be leveraged, making it difficult to exploit but potentially devastating if successful.

Generated by OpenCVE AI on August 4, 2026 at 02:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle iSupport patch or upgrade to a version later than 12.2.15, ensuring the flaw is addressed.
  • Restrict network access to the iSupport HTTP endpoints to trusted IP addresses or networks, preferably via firewall or VPN controls.
  • Disable or remove the Internal Operations component if it is not required, or restrict user permissions so that only necessary users can access it.
  • Monitor logs for anomalous privilege escalation activity and investigate promptly.

Generated by OpenCVE AI on August 4, 2026 at 02:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title High-Privilege Remote Takeover of Oracle iSupport

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title High Privilege Escalation and Takeover via HTTP in Oracle iSupport

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title High Privilege Escalation and Takeover via HTTP in Oracle iSupport
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle isupport
CPEs cpe:2.3:a:oracle:isupport:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isupport
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:18:32.489Z

Reserved: 2026-07-08T15:51:55.593Z

Link: CVE-2026-60826

cve-icon Vulnrichment

Updated: 2026-07-24T15:03:44.493Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:20.567

Modified: 2026-07-31T17:46:57.120

Link: CVE-2026-60826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:45:02Z

Weaknesses