Junglewise Threat Intelligence

CVE-2026-60619: Oracle JD Edwards EnterpriseOne HCM Foundation compromise in Time Accounting and HRM Base

CVE-2026-60619 · Severity: high · CVSS 7.5 · Published 2026-07-21

Vendors: Oracle.

Executive brief

Oracle JD Edwards EnterpriseOne HCM Foundation, a suite used for human capital management and payroll operations, contains a security vulnerability in its Time Accounting and HRM Base components. An attacker with basic user credentials could potentially exploit this flaw over the network to gain full control of the application. A successful attack could lead to the unauthorized access, modification, or deletion of sensitive employee and financial data, resulting in a complete compromise of the system's integrity and availability.

Technical details

A vulnerability exists in the Time Accounting and HRM Base components of Oracle JD Edwards EnterpriseOne HCM Foundation version 9.2. The flaw allows a low-privileged attacker with network access via HTTP to compromise the application. While the attack complexity is rated as high, suggesting specific conditions or timing may be required, a successful exploit results in a complete takeover of the affected component (Confidentiality, Integrity, and Availability impacts). The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle JD Edwards EnterpriseOne HCM Foundation 9.2

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60619 by Oracle.

References

Related threats