A low-privilege, network-exploitable vulnerability in Oracle Application Object Library carries a CVSS 9.6 rating and can compromise data well beyond the affected component due to a scope change.
What Is It
CVE-2026-60773 is a critical vulnerability in the Oracle Application Object Library product (Core component) of Oracle E-Business Suite. Oracle describes it as easily exploitable, allowing a low-privileged attacker with network access via HTTPS to compromise Application Object Library. Because the flaw involves a scope change, successful attacks may significantly impact additional products beyond the vulnerable component. Exploitation can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all Application Object Library accessible data.
Why It Matters
The CVSS 3.1 base score is 9.6 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N. The combination of network attack vector, low attack complexity, only low privileges required, and no user interaction makes this readily exploitable. High confidentiality and integrity impacts, paired with the scope change, mean an attacker can reach and manipulate data across affected products; a serious risk for enterprises running E-Business Suite. The supplied KEV data is empty, so there is no confirmation of active exploitation in the provided source material.
What's Vulnerable
- Product: Oracle Application Object Library (component: Core), part of Oracle E-Business Suite
- Vendor: Oracle Corporation
- Affected versions: 12.2.3 through 12.2.15
Patch Status
Oracle disclosed this vulnerability as part of its Critical Patch Update for July 2026. The referenced Oracle Critical Patch Update advisory is the authoritative source for fixed versions and remediation; organizations running affected E-Business Suite versions should apply the July 2026 CPU updates. No separate CISA-required remediation action is present in the supplied data.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60773, https://nvd.nist.gov/vuln/detail/CVE-2026-60773