Impact
CVE-2026-60826 describes an access‑control flaw, identified as CWE‑284, in Oracle iSupport’s Internal Operations component that allows a high‑privileged attacker with HTTP network access to compromise the application. The vulnerability, classified as medium severity with a CVSS 3.1 Base Score of 6.6, can lead to full system takeover, exposing confidential data and disrupting integrity and availability. The vector indicates that a successful exploit requires an attacker with high‑level privileges and access to the iSupport HTTP endpoints.
Affected Systems
The affected product is Oracle iSupport, part of Oracle E‑Business Suite. Oracle Corporation’s iSupport component is impacted in supported releases 12.2.3 through 12.2.15. No further version detail is disclosed beyond the nominal range in the public advisory.
Risk and Exploitability
The CVSS score of 6.6 places the issue in the medium severity band, yet the EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, indicating that no confirmed exploits have been reported. An attacker would typically target the iSupport HTTP endpoints and must already possess high privileges or a privileged foothold before the flaw can be leveraged, making it difficult to exploit but potentially devastating if successful.
OpenCVE Enrichment