CVE-2026-60782 – Oracle Payments

CVSS 9.8 CRITICAL Critical - Same Day Deployment

“An unauthenticated HTTP request can result in complete takeover of Oracle Payments.”

Oracle addresses a Critical vulnerability in the File Transmission component of Oracle Payments within Oracle E-Business Suite. CVE-2026-60782 allows an unauthenticated attacker with network access over HTTP to compromise Oracle Payments, with successful exploitation resulting in takeover of the application. The CVSS score is 9.8, which is Critical severity.

Affected releases are Oracle E-Business Suite 12.2.3 through 12.2.15. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.

Key Details

Affected Product
Oracle Payments
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-306
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.