Junglewise Threat Intelligence

CVE-2026-60490: Oracle JD Edwards EnterpriseOne CRM Foundation compromise vulnerability

CVE-2026-60490 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle JD Edwards EnterpriseOne CRM Foundation. Vendors: Oracle.

Executive brief

A vulnerability in Oracle's JD Edwards EnterpriseOne CRM Foundation allows an attacker with basic user access to take full control of the system. This software is used by businesses to manage customer relationships and sales data. A successful exploit could lead to the theft of sensitive customer information, unauthorized modification of business records, or a complete shutdown of the CRM service.

Technical details

This vulnerability affects the CRM Foundation component of Oracle JD Edwards EnterpriseOne version 9.2. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw allows an attacker to bypass security controls to achieve a complete takeover of the affected component, impacting confidentiality, integrity, and availability. While the specific CWE is not detailed in the advisory, the CVSS vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates a high-impact remote exploit. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle JD Edwards EnterpriseOne CRM Foundation 9.2

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.

References

Related threats