Junglewise Threat Intelligence

CVE-2026-60496: Oracle JD Edwards EnterpriseOne Advanced Pricing compromise via JDENET

CVE-2026-60496 · Severity: high · CVSS 7.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability in Oracle JD Edwards EnterpriseOne Advanced Pricing could allow an attacker to take full control of the procurement pricing system. This component is used by businesses to manage complex pricing rules and procurement logic; a successful exploit could lead to unauthorized changes in pricing data, loss of sensitive procurement information, or service disruption. While the attack requires an existing low-level user account and is considered difficult to execute, it poses a significant risk to the integrity of financial and supply chain operations.

Technical details

This vulnerability affects the Advanced Pricing component of Oracle JD Edwards EnterpriseOne version 9.2. It is a network-based attack that utilizes the JDENET protocol. The exploit is characterized as having high complexity (AC:H), meaning it may require specific timing or environmental conditions to succeed. An attacker must have low-privileged credentials (PR:L) to initiate the attack. If successful, the vulnerability allows for a complete compromise of the component, impacting confidentiality, integrity, and availability (C:H/I:H/A:H). Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle JD Edwards EnterpriseOne Advanced Pricing - Procurement 9.2

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD entry created

References