Junglewise Threat Intelligence

CVE-2026-60338: Oracle Project Manufacturing data manipulation in PJM Command Center

CVE-2026-60338 · Severity: low · CVSS 3.6 · Published 2026-07-21

Technologies: Oracle Project Manufacturing. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Project Manufacturing component of the Oracle E-Business Suite, which is used by organizations to manage complex manufacturing projects. A low-privileged user with existing access to the underlying system could potentially modify or delete project data and cause minor service disruptions. While the impact is limited to data integrity and availability, it could interfere with accurate project tracking and reporting.

Technical details

This vulnerability affects the PJM Command Center component within Oracle Project Manufacturing (Oracle E-Business Suite) version V16. It is classified as difficult to exploit, requiring a low-privileged attacker to have local logon access to the infrastructure where the software executes. Successful exploitation allows an attacker to perform unauthorized updates, insertions, or deletions of accessible data, and can lead to a partial denial of service (DoS). The vulnerability is tracked via Oracle's July 2026 Critical Patch Update, and users are advised to apply the relevant security patches provided by the vendor.

Affected products

  • Oracle Project Manufacturing (PJM Command Center) V16

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60338 by Oracle.
  • 2026-07-21: advisory: Included in Oracle Critical Patch Update Advisory - July 2026.

References

Related threats