VDB
CVE-2026-60880
CVE-2026-60880
PUBLISHED
CVSS 9.8 CRITICAL
Reported by oracle · Published July 21, 2026
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Risk Scores
CVSS 3.1
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corporation | Oracle Work in Process | 12.2.3 |
| Oracle Corporation | Oracle Work in Process | 12.2.3, 12.2.3 |
| oracle | work_in_process | 12.2.3, 12.2.3 |
Timeline
- Jul 21, 2026 CVE Published
- Jul 22, 2026 Coalition ESS Score
- Jul 28, 2026 CVE Updated
- Aug 7, 2026 EPSS Score
References
- Oracle Advisory vendor-advisory