Junglewise Threat Intelligence

CVE-2026-60489: Oracle JD Edwards EnterpriseOne CRM Foundation system takeover

CVE-2026-60489 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle JD Edwards EnterpriseOne CRM Foundation. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's JD Edwards EnterpriseOne CRM Foundation, a software suite used by businesses to manage customer relationships and sales data. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the system. This could lead to the theft of sensitive customer information, unauthorized modification of business records, or a total disruption of CRM operations.

Technical details

A vulnerability in the CRM Foundation component of Oracle JD Edwards EnterpriseOne version 9.2 allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. While the specific CWE is not identified in the advisory, the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates a high impact on confidentiality, integrity, and availability without requiring user interaction. This vulnerability was disclosed as part of the Oracle Critical Patch Update (CPU) for July 2026. Organizations should apply the latest security updates from Oracle to mitigate this risk.

Affected products

  • Oracle JD Edwards EnterpriseOne CRM Foundation 9.2

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats