Junglewise Threat Intelligence

CVE-2026-60339: Oracle E-Business Suite information disclosure in Project Manufacturing

CVE-2026-60339 · Severity: low · CVSS 3.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Project Manufacturing component of Oracle E-Business Suite, a suite of business applications used for managing large-scale manufacturing projects. An attacker with low-level access to the corporate network could potentially view sensitive manufacturing data that they are not authorized to see. While the vulnerability is difficult to exploit, it could lead to the unauthorized disclosure of internal project information.

Technical details

An information disclosure vulnerability exists in the PJM Command Center component of Oracle Project Manufacturing (Oracle E-Business Suite). The flaw allows a low-privileged attacker with network access via HTTP to compromise the system. Exploitation is considered difficult (High Attack Complexity), but if successful, it enables the attacker to gain unauthorized read access to a subset of Oracle Project Manufacturing data. The vulnerability affects version V16 and was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle E-Business Suite (Project Manufacturing) V16

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References