A vulnerability was found in Oracle Project Foundation up to 12.2.15. It has been rated as critical. Impacted is an unknown function of the component Project Definition. This manipulation causes improper privilege management.

This vulnerability is handled as CVE-2026-60587. The attack can be initiated remotely. There is not any exploit available.