Junglewise Threat Intelligence

CVE-2026-60321: Oracle Project Manufacturing data compromise in PJM Command Center

CVE-2026-60321 · Severity: medium · CVSS 5.7 · Published 2026-07-21

Technologies: Oracle Project Manufacturing. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle Project Manufacturing, a component of the Oracle E-Business Suite used by organizations to manage complex manufacturing projects. An attacker with high-level access to the underlying server could exploit this flaw to gain full access to sensitive project data. This could lead to the unauthorized viewing, modification, or deletion of critical business information, potentially disrupting manufacturing operations and compromising proprietary data.

Technical details

A vulnerability in the Oracle Project Manufacturing product (specifically the PJM Command Center component) of Oracle E-Business Suite allows for unauthorized data access and modification. The flaw is categorized as difficult to exploit (AC:H) and requires the attacker to have high-level privileges (PR:H) and local logon access to the infrastructure where the software executes. Successful exploitation enables an attacker to gain complete confidentiality and integrity impacts over all data accessible to the Project Manufacturing module. The vulnerability affects version V16 and was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Project Manufacturing (PJM Command Center) V16

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update published

References

Related threats