Junglewise Threat Intelligence

CVE-2026-60337: Oracle Project Manufacturing data compromise in PJM Command Center

CVE-2026-60337 · Severity: medium · CVSS 4.7 · Published 2026-07-21

Technologies: Oracle Project Manufacturing. Vendors: Oracle.

Executive brief

A security vulnerability exists in the Oracle Project Manufacturing component of the Oracle E-Business Suite, which is used by organizations to manage complex manufacturing projects. A highly privileged attacker with existing access to the underlying server infrastructure could exploit this flaw to gain unauthorized access to sensitive project data. While difficult to execute, a successful attack could lead to the theft of critical business information or the unauthorized modification of manufacturing records.

Technical details

This vulnerability affects the PJM Command Center component within Oracle Project Manufacturing version V16. It is classified as a local attack requiring high privileges (PR:H) and high complexity (AC:H), meaning the attacker must already have significant access to the infrastructure where the software executes. Successful exploitation allows for unauthorized read access to all accessible data (Confidentiality) and unauthorized update, insert, or delete access to some data (Integrity). The vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle Project Manufacturing V16

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats