Description
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in takeover of Oracle Property Manager. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Property Manager’s Internal Operations component allows a high‑privileged attacker with network access via HTTP to compromise the application. If successfully exploited, the attacker can gain complete control over Oracle Property Manager, resulting in total loss of confidentiality, integrity, and availability for that system. The weakness is an authorization failure (CWE‑284).

Affected Systems

Oracle Property Manager, part of Oracle E‑Business Suite, versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS base score of 7.2 indicates a high‑severity issue. The EPSS score is below one percent, suggesting limited exploitation activity to date, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS vector (AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) points to a remote, low‑complexity attack that requires the attacker to possess high‑level privileges, typically attainable through credential compromise or a pre‑existing privileged account. Consequently, the attack is likely to occur over HTTP from an externally reachable location, and mitigating network exposure combined with timely patching is the most effective defense.

Generated by OpenCVE AI on August 4, 2026 at 02:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July‑2026 patch for Oracle Property Manager that addresses CVE‑2026‑60910
  • Limit HTTP access to the Oracle Property Manager application to trusted internal networks or VPN endpoints
  • Enforce the principle of least privilege, ensuring that high‑privilege accounts are tightly controlled and monitored for suspicious activity

Generated by OpenCVE AI on August 4, 2026 at 02:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Property Manager Allows Full System Takeover

Thu, 30 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Property Manager Allows Full System Takeover

Mon, 27 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Property Manager via HTTP

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Takeover Vulnerability in Oracle Property Manager via HTTP

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in takeover of Oracle Property Manager. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle property Manager
CPEs cpe:2.3:a:oracle:property_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle property Manager
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Property Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:18:31.761Z

Reserved: 2026-07-08T15:51:55.601Z

Link: CVE-2026-60910

cve-icon Vulnrichment

Updated: 2026-07-24T17:18:25.340Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses