CVE-2026-60738
Oracle · Oracle Installed Base
A vulnerability in the Create Item Instance component of Oracle Installed Base allows authenticated attackers with network access to achieve full system takeover.
Executive summary
A critical vulnerability in Oracle Installed Base allows low privileged attackers to compromise the application, resulting in potential full system takeover.
Vulnerability
This is an easily exploitable vulnerability that allows a low privileged, authenticated attacker with network access via HTTP to compromise the application. The flaw resides within the Create Item Instance component.
Business impact
The successful exploitation of this vulnerability can result in the complete takeover of the Oracle Installed Base module. Given the CVSS score of 8.8, this poses a significant risk to data integrity, confidentiality, and operational availability, potentially leading to unauthorized access to sensitive business records or system manipulation.
Remediation
Immediate Action: Apply the security updates provided by Oracle in the July 2026 Critical Patch Update.
Proactive Monitoring: Review application access logs for unusual activity associated with the Create Item Instance component.
Compensating Controls: Implement Web Application Firewall rules to detect and block suspicious HTTP requests targeting the affected module.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high severity of this vulnerability necessitates immediate attention. Administrators must prioritize the application of the vendor patches to mitigate the risk of unauthorized system takeover.