CVE-2026-60337 Overview
CVE-2026-60337 affects the Oracle Project Manufacturing product within Oracle E-Business Suite, specifically the PJM Command Center component. The supported version affected is V16. A high-privileged attacker with local logon access to the infrastructure where Oracle Project Manufacturing executes can compromise the application.
Successful exploitation grants unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data. Attackers can also perform unauthorized update, insert, or delete operations on a subset of that data. The vulnerability requires high attack complexity and does not rely on user interaction.
Critical Impact
Local attackers with high privileges can access all Oracle Project Manufacturing data and modify a subset of records, breaching confidentiality and integrity of manufacturing operations.
Affected Products
- Oracle E-Business Suite
- Oracle Project Manufacturing V16
- PJM Command Center component
Discovery Timeline
- 2026-07-21 - CVE-2026-60337 published to NVD
- 2026-07-23 - Last updated in NVD database
Technical Details for CVE-2026-60337
Vulnerability Analysis
The vulnerability resides in the PJM Command Center component of Oracle Project Manufacturing, a module of the Oracle E-Business Suite. The flaw allows a locally authenticated attacker holding elevated privileges to compromise application data.
Exploitation results in two distinct impacts. First, the attacker gains full read access to all data reachable by Oracle Project Manufacturing. Second, the attacker can insert, update, or delete a subset of that data. Availability of the service is not impacted.
Oracle rates the flaw with high attack complexity, indicating that specific conditions beyond authentication must be met for a successful attack. The EPSS score is 0.123%, placing exploitation likelihood in the low probability range.
Root Cause
Oracle has not publicly disclosed the specific technical root cause. Based on the CVSS metrics, the weakness stems from insufficient access controls or input handling within the PJM Command Center that permits a privileged local user to reach data outside their intended authorization boundary.
Attack Vector
The attack vector is local. An adversary must authenticate to the infrastructure hosting Oracle Project Manufacturing with high privileges before triggering the flaw. No user interaction from another party is required, and the scope remains unchanged after exploitation.
Refer to the Oracle Security Alert July 2026 for vendor-provided technical context.
Detection Methods for CVE-2026-60337
Indicators of Compromise
- Unexpected read queries against PJM Command Center tables from high-privilege accounts outside routine business hours.
- Bulk insert, update, or delete operations on Project Manufacturing records not tied to documented change tickets.
- Anomalous logon activity to the Oracle E-Business Suite application tier from accounts with elevated database roles.
Detection Strategies
- Enable Oracle E-Business Suite audit trails on Project Manufacturing tables and monitor for unusual data access patterns.
- Correlate application-tier logon events with database sessions to identify privilege misuse targeting the PJM Command Center.
- Baseline normal query volumes for privileged accounts and alert on statistical deviations.
Monitoring Recommendations
- Forward Oracle E-Business Suite audit and database listener logs to a centralized SIEM for correlation and retention.
- Monitor privileged account creation, role grants, and password changes on hosts running Oracle Project Manufacturing.
- Track file integrity on Oracle application tier binaries and configuration files.
How to Mitigate CVE-2026-60337
Immediate Actions Required
- Apply the July 2026 Oracle Critical Patch Update to affected Oracle E-Business Suite deployments running Project Manufacturing V16.
- Review and reduce the number of accounts with high-privilege local access to Oracle Project Manufacturing infrastructure.
- Audit existing privileged account activity in PJM Command Center for signs of prior misuse.
Patch Information
Oracle addressed CVE-2026-60337 in the July 2026 Critical Patch Update. Administrators should follow the guidance in the Oracle Security Alert July 2026 advisory to identify the appropriate patch bundle for their environment and apply it during a scheduled maintenance window.
Workarounds
- Restrict local logon access to Oracle Project Manufacturing hosts using operating system and network controls until patching is complete.
- Enforce least privilege on Oracle E-Business Suite responsibilities that grant access to PJM Command Center functions.
- Enable enhanced audit logging on Project Manufacturing schemas to detect exploitation attempts prior to remediation.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

