Summary
CVE-2026-60880 is a critical unauthenticated remote code execution vulnerability (CVSS 9.8) affecting the Oracle Work in Process module — specifically its Internal Operations component — within Oracle E-Business Suite, versions 12.2.3 through 12.2.15. Disclosed as part of Oracle’s July 2026 Critical Patch Update, the flaw allows a remote, unauthenticated attacker to fully compromise the affected module via HTTP, with high impact to confidentiality, integrity, and availability.
Technical details
- Affected component: Internal Operations within Oracle Work in Process (Oracle E-Business Suite)
- Attack vector: Exploitable remotely over HTTP — no local access, no prior privileges, and no user interaction required (AV:N, AC:L, PR:N, UI:N)
- Trigger conditions: Any unauthenticated attacker with network access to the Oracle EBS HTTP interface can trigger the vulnerability directly, with low attack complexity
- Impact: Successful exploitation can result in complete takeover of the Oracle Work in Process module, enabling remote code execution with high impact to confidentiality, integrity, and availability (C:H/I:H/A:H)
Affected software
- Oracle Work in Process (Oracle E-Business Suite), versions 12.2.3 through 12.2.15
Severity
CVSS v3.1 Base Score: 9.8 (CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the security patches included in Oracle’s July 2026 Critical Patch Update, which addresses CVE-2026-60880. The official advisory and patch instructions are available at the Oracle CPU July 2026 advisory
- Organizations running Oracle E-Business Suite instances directly accessible from the internet should treat patching as an emergency priority — research has confirmed that over 900 Oracle EBS instances are directly reachable from the public internet, making internet-exposed deployments high-value targets
- Where immediate patching is not feasible, restrict network-level access to Oracle EBS HTTP interfaces to trusted IP ranges and internal networks only as an interim measure
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

