CVE-2026-60829: High severity Oracle Oracle E-Business Suite - Advanced Outbound Telephony vulnerability
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Advanced Outbound Telephony (Oracle E-Business Suite) - Internal Operationsto a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60829?
CVE-2026-60829 has a high severity score of 8.8.
How do I fix CVE-2026-60829?
To fix CVE-2026-60829, update Oracle Advanced Outbound Telephony to a version higher than 12.2.15.
What type of vulnerability is CVE-2026-60829?
CVE-2026-60829 is an easily exploitable vulnerability that allows a low privileged attacker to compromise Oracle Advanced Outbound Telephony.
Who is affected by CVE-2026-60829?
CVE-2026-60829 affects users of Oracle E-Business Suite versions 12.2.3 to 12.2.15.
What are the potential impacts of CVE-2026-60829?
The potential impacts of CVE-2026-60829 include complete compromise of the system with high confidentiality, integrity, and availability risks.