A critical (CVSS 9.8) flaw in Oracle Work in Process, part of Oracle E-Business Suite, lets an unauthenticated remote attacker fully compromise the product over HTTP.
What Is It
CVE-2026-60880 is a vulnerability in the Oracle Work in Process product of Oracle E-Business Suite, specifically within the Internal Operations component. According to Oracle, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. A successful attack can result in complete takeover of the product. The CVSS 3.1 base score is 9.8 (CRITICAL), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning network-reachable, low complexity, no privileges, and no user interaction required.
Why It Matters
The combination of unauthenticated network exploitation and full confidentiality, integrity, and availability impact places this at the top of the severity scale. Oracle E-Business Suite is widely deployed for core enterprise operations, so a takeover of the Work in Process module could expose sensitive manufacturing and business data, allow tampering, or disrupt availability. The maximum exploitability score (3.9) underscores how little effort an attacker needs.
Note: No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.
What's Vulnerable
- Product: Oracle Work in Process (Oracle E-Business Suite)
- Component: Internal Operations
- Vendor: Oracle Corporation
- Affected versions: 12.2.3 through 12.2.15
Patch Status
The vulnerability is addressed in Oracle's Critical Patch Update for July 2026. Organizations running affected Oracle Work in Process versions (12.2.3–12.2.15) should apply the fixes referenced in the July 2026 CPU advisory. The NVD record lists a vulnerability status of "Received" as of its July 21, 2026 publication.