Junglewise Threat Intelligence

CVE-2026-60499: Oracle JD Edwards EnterpriseOne Solution Advisor remote compromise

CVE-2026-60499 · Severity: high · CVSS 8.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle JD Edwards EnterpriseOne Solution Advisor, a tool used by businesses to manage and resolve customer service issues, contains a high-severity vulnerability. An attacker with basic user access to the corporate network can exploit this flaw to take full control of the application. This could lead to the theft of sensitive business data, unauthorized modification of records, or a complete shutdown of the service.

Technical details

A vulnerability in the Solution Advisor component of Oracle JD Edwards EnterpriseOne version 9.2 allows for a complete system compromise. The flaw is categorized as easily exploitable and requires only low-privileged user credentials to execute. The attack vector is network-based via HTTP, and no user interaction is required. Successful exploitation grants the attacker full control over the Solution Advisor, leading to high impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle JD Edwards EnterpriseOne Solution Advisor 9.2

Timeline

  • 2026-07-21: advisory: NVD published the CVE record based on Oracle's July 2026 CPU.
  • 2026-07-21: disclosed: Vulnerability disclosed in Oracle Critical Patch Update.

References