Junglewise Threat Intelligence

CVE-2026-60495: Oracle JD Edwards EnterpriseOne compromise in Requirements Planning

CVE-2026-60495 · Severity: high · CVSS 7.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's JD Edwards EnterpriseOne Requirements Planning software, which is used by businesses to manage supply chain and production schedules. An attacker with basic user access to the network could exploit this flaw to take full control of the planning system. This could lead to the theft of sensitive business data, disruption of manufacturing operations, or unauthorized changes to resource planning.

Technical details

A vulnerability in the Requirements Planning component of Oracle JD Edwards EnterpriseOne version 9.2 allows for a complete system takeover. The flaw is exploitable by a low-privileged attacker with network access via the JDENET protocol. While the attack complexity is rated as high, a successful exploit grants the attacker full control over the Confidentiality, Integrity, and Availability of the affected component. Users are advised to refer to the Oracle Critical Patch Update (CPU) for July 2026 for remediation steps.

Affected products

  • Oracle JD Edwards EnterpriseOne Requirements Planning 9.2

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD record published

References