Description
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Project Portfolio Analysis allows an attacker with low privileges but network access via HTTP to override access controls and create, modify, or delete critical data. This improper access control can compromise both confidentiality and integrity of all data the application protects. The weakness is classed as CWE‑284 and scored highly with a CVSS 3.1 base score of 8.1.

Affected Systems

The vulnerability affects Oracle Corporation’s Oracle Project Portfolio Analysis product of Oracle E‑Business Suite. Versions from 12.2.3 up to 12.2.15 are impacted.

Risk and Exploitability

The exploit can be achieved over the public network with minimal effort from a low‑privileged user, and it requires no special software beyond a web client. The likely attack vector is inferred to be HTTP requests originating from an external network, as the description mentions network access via HTTP. Although the EPSS score is reported as less than 1 % – indicating low current exploitation probability – the high CVSS score and lack of KEV listing do not diminish the importance of remediation, as an attacker could readily gain valuable data or disrupt operations once the flaw is exploited.

Generated by OpenCVE AI on August 4, 2026 at 02:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU July 2026 patch for Oracle Project Portfolio Analysis to fix the improper access control issue
  • If patching cannot be performed immediately, limit HTTP access to the application to trusted internal hosts only and block all other external network traffic
  • Implement temporary RBAC restrictions that prevent low‑privileged users from creating, deleting, or modifying critical data until the patch is in place

Generated by OpenCVE AI on August 4, 2026 at 02:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Project Portfolio Analysis Leads to Unauthorized Data Modification

Sat, 01 Aug 2026 05:15:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Project Portfolio Analysis Leads to Unauthorized Data Modification

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Remote Access Vulnerability Allowing Low‑Privileged Attackers to Modify or Delete Critical Data in Oracle Project Portfolio Analysis

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Access Vulnerability Allowing Low‑Privileged Attackers to Modify or Delete Critical Data in Oracle Project Portfolio Analysis
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Portfolio Analysis accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Portfolio Analysis accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle project Portfolio Analysis
CPEs cpe:2.3:a:oracle:project_portfolio_analysis:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle project Portfolio Analysis
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Project Portfolio Analysis
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:15:40.578Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60986

cve-icon Vulnrichment

Updated: 2026-07-24T15:15:28.913Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses