CVE-2026-60684 | Oracle Applications Framework up to 12.2.15 Upload Attachments improper authorization
A vulnerability has been found in Oracle Applications Framework up to 12.2.15 and classified as critical. The impacted element is an unknown function of the component Upload Attachments. This manipulation causes improper authorization.
This vulnerability is registered as CVE-2026-60684. Remote exploitation of the attack is possible. No exploit is available.