CVE-2026-60776: Medium severity Oracle Oracle E-Business Suite - Oracle Application Object Library (AOL Generic Loader) vulnerability
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: AOL Generic Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object Library. Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - Oracle Application Object Library (AOL Generic Loader)to a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15 - Compensating control
Restrict access to the Oracle E-Business Suite host/network so that only authorized users can log on where Oracle Application Object Library executes.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60776?
CVE-2026-60776 has a medium severity score of 6.7.
How do I fix CVE-2026-60776?
To fix CVE-2026-60776, apply the latest security patches provided by Oracle for affected versions.
Who is affected by CVE-2026-60776?
Users of Oracle E-Business Suite versions 12.2.3 to 12.2.15 are affected by CVE-2026-60776.
What kind of vulnerability is CVE-2026-60776?
CVE-2026-60776 is an easily exploitable vulnerability that allows high privileged attackers to compromise the Oracle Application Object Library.
What components are impacted by CVE-2026-60776?
CVE-2026-60776 affects the AOL Generic Loader component of Oracle Application Object Library in Oracle E-Business Suite.