Oracle's July 2026 Critical Patch Update discloses CVE-2026-60540, a CVSS 9.6 vulnerability in Oracle SOA Suite that lets a low-privileged network attacker read and alter all accessible data, with impact extending beyond the product itself.
What Is It
CVE-2026-60540 is a critical vulnerability in the Oracle SOA Suite product of Oracle Fusion Middleware, specifically in the Integration Business Insight component. The flaw is described by Oracle as easily exploitable, allowing a low-privileged attacker with network access via HTTP to compromise Oracle SOA Suite. Because the vulnerability carries a scope change (CVSS S:C), successful attacks may significantly impact additional products beyond SOA Suite itself. It carries a CVSS 3.1 base score of 9.6 (CRITICAL) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N.
Why It Matters
The attack requires only low privileges, no user interaction, and network access over HTTP, a low bar for exploitation. Successful attacks can result in unauthorized creation, deletion, or modification of critical data (or all SOA Suite–accessible data), as well as unauthorized access to critical or complete data. The CVSS vector reflects HIGH confidentiality and HIGH integrity impact; availability is not affected (A:N). The scope change is notable, since compromise can ripple into other connected products. This CVE is not currently listed in the CISA KEV catalog, so there is no confirmed evidence of active exploitation in the supplied source material.
What's Vulnerable
- Product: Oracle SOA Suite (Oracle Fusion Middleware)
- Component: Integration Business Insight
- Vendor: Oracle Corporation
- Affected versions: 12.2.1.4.0 and 14.1.2.0.0
Patch Status
Oracle addresses CVE-2026-60540 in its July 2026 Critical Patch Update (CPU). Organizations running the affected SOA Suite versions should apply the fixes published in the Oracle Critical Patch Update Advisory for July 2026. No mandated remediation deadline is present in the supplied source material.
Sources
- Oracle Critical Patch Update Advisory, July 2026, https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60540, https://nvd.nist.gov/vuln/detail/CVE-2026-60540