Junglewise Threat Intelligence

CVE-2026-60336: Oracle Project Manufacturing data compromise in PJM Command Center

CVE-2026-60336 · Severity: medium · CVSS 5.7 · Published 2026-07-21

Technologies: Oracle Project Manufacturing. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle Project Manufacturing, a component of the Oracle E-Business Suite used by organizations to manage complex manufacturing projects. A highly privileged attacker with existing access to the underlying server infrastructure could exploit this flaw to gain full access to project data. This could result in the unauthorized viewing, modification, or deletion of sensitive business information, potentially disrupting manufacturing operations and compromising data integrity.

Technical details

This vulnerability affects the PJM Command Center component of Oracle Project Manufacturing version V16. It is characterized by a high complexity of exploitation and requires the attacker to have high-level privileges and local logon access to the infrastructure where the software executes. If successfully exploited, the attacker can achieve complete confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of all accessible data within the Project Manufacturing module. The vulnerability is tracked as part of the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Project Manufacturing (PJM Command Center) V16

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats