Executive brief
A vulnerability exists in Oracle's JD Edwards EnterpriseOne Procurement and Subcontract Management system, which is used by organizations to manage purchasing and vendor contracts. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the procurement system. This could lead to the unauthorized modification of financial records, exposure of sensitive supplier data, or a total disruption of procurement operations.
Technical details
A vulnerability in the Procurement component of Oracle JD Edwards EnterpriseOne Procurement and Subcontract Management (version 9.2) allows for a complete system takeover. The flaw is categorized as easily exploitable and requires only low-privileged authentication to execute via HTTP over a network. Successful exploitation grants the attacker full access to Confidentiality, Integrity, and Availability (CIA) of the affected component. While the specific CWE is not listed in the advisory, the impact and vector suggest a significant authorization or injection flaw within the web-based procurement interface. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle JD Edwards EnterpriseOne Procurement and Subcontract Management 9.2
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60618
- 2026-07-21: advisory: Oracle released security alert cpujul2026.html