SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60773 2026-07-21

CVE-2026-60773: Critical Flaw in Oracle E-Business Suite Application Object Library

"A low-privilege, network-exploitable vulnerability in Oracle Application Object Library carries a CVSS 9.6 rating and can compromise data well beyond the affected component due to a scope change."

A low-privilege, network-exploitable vulnerability in Oracle Application Object Library carries a CVSS 9.6 rating and can compromise data well beyond the affected component due to a scope change.

What Is It

CVE-2026-60773 is a critical vulnerability in the Oracle Application Object Library product (Core component) of Oracle E-Business Suite. Oracle describes it as easily exploitable, allowing a low-privileged attacker with network access via HTTPS to compromise Application Object Library. Because the flaw involves a scope change, successful attacks may significantly impact additional products beyond the vulnerable component. Exploitation can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized read access to all Application Object Library accessible data.

Why It Matters

The CVSS 3.1 base score is 9.6 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N. The combination of network attack vector, low attack complexity, only low privileges required, and no user interaction makes this readily exploitable. High confidentiality and integrity impacts, paired with the scope change, mean an attacker can reach and manipulate data across affected products; a serious risk for enterprises running E-Business Suite. The supplied KEV data is empty, so there is no confirmation of active exploitation in the provided source material.

What's Vulnerable

Patch Status

Oracle disclosed this vulnerability as part of its Critical Patch Update for July 2026. The referenced Oracle Critical Patch Update advisory is the authoritative source for fixed versions and remediation; organizations running affected E-Business Suite versions should apply the July 2026 CPU updates. No separate CISA-required remediation action is present in the supplied data.

Sources