SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60880 2026-07-21

CVE-2026-60880: Critical Unauthenticated Takeover in Oracle E-Business Suite Work in Process

"A critical (CVSS 9.8) flaw in Oracle Work in Process, part of Oracle E-Business Suite, lets an unauthenticated remote attacker fully compromise the product over HTTP."

A critical (CVSS 9.8) flaw in Oracle Work in Process, part of Oracle E-Business Suite, lets an unauthenticated remote attacker fully compromise the product over HTTP.

What Is It

CVE-2026-60880 is a vulnerability in the Oracle Work in Process product of Oracle E-Business Suite, specifically within the Internal Operations component. According to Oracle, it is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. A successful attack can result in complete takeover of the product. The CVSS 3.1 base score is 9.8 (CRITICAL), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning network-reachable, low complexity, no privileges, and no user interaction required.

Why It Matters

The combination of unauthenticated network exploitation and full confidentiality, integrity, and availability impact places this at the top of the severity scale. Oracle E-Business Suite is widely deployed for core enterprise operations, so a takeover of the Work in Process module could expose sensitive manufacturing and business data, allow tampering, or disrupt availability. The maximum exploitability score (3.9) underscores how little effort an attacker needs.

Note: No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.

What's Vulnerable

Patch Status

The vulnerability is addressed in Oracle's Critical Patch Update for July 2026. Organizations running affected Oracle Work in Process versions (12.2.3–12.2.15) should apply the fixes referenced in the July 2026 CPU advisory. The NVD record lists a vulnerability status of "Received" as of its July 21, 2026 publication.

Sources