CVE-2026-60172

Vulnerability in Oracle Autonomous Health Framework (component: Developer triaging platform). Supported versions that are affected are 26.0.0, 26.1.0 and 26.2.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:autonomous_health_framework:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.2.0:*:*:*:*:*:*:*

History

06 Aug 2026, 14:50

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:autonomous_health_framework:26.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.2.0:*:*:*:*:*:*:*
First Time Oracle
Oracle autonomous Health Framework
References () https://www.oracle.com/security-alerts/cpujul2026.html - () https://www.oracle.com/security-alerts/cpujul2026.html - Vendor Advisory

23 Jul 2026, 17:16

Type Values Removed Values Added
CWE CWE-284

21 Jul 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-21 22:17

Updated : 2026-08-06 14:50


NVD link : CVE-2026-60172

Mitre link : CVE-2026-60172

CVE.ORG link : CVE-2026-60172


JSON object : View

Products Affected

oracle

  • autonomous_health_framework
CWE
CWE-284

Improper Access Control