Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-60339

CVE-2026-60339: Oracle Project Manufacturing Vulnerability

CVE-2026-60339 is an information disclosure vulnerability in Oracle Project Manufacturing that allows unauthorized access to sensitive data. This article covers the technical details, affected versions, and mitigation strategies.

Updated:

CVE-2026-60339 Overview

CVE-2026-60339 affects the Oracle Project Manufacturing product within Oracle E-Business Suite, specifically the PJM Command Center component. The supported version affected is V16. A low-privileged attacker with network access via HTTP can exploit this flaw, though exploitation is difficult due to high attack complexity. Successful exploitation results in unauthorized read access to a subset of Oracle Project Manufacturing accessible data. The issue is classified as an information disclosure vulnerability impacting confidentiality only, with no integrity or availability impact.

Critical Impact

Authenticated remote attackers can read a subset of data from Oracle Project Manufacturing PJM Command Center in E-Business Suite V16.

Affected Products

  • Oracle E-Business Suite - Oracle Project Manufacturing
  • Component: PJM Command Center
  • Supported version affected: V16

Discovery Timeline

Technical Details for CVE-2026-60339

Vulnerability Analysis

The vulnerability resides in the PJM Command Center component of Oracle Project Manufacturing. An authenticated attacker holding low privileges within the E-Business Suite environment can send crafted HTTP requests to interact with the component. Exploitation is described by Oracle as difficult, indicating conditions outside the attacker's direct control must be met. Impact is limited to confidentiality — the attacker gains unauthorized read access to a subset of application data. Integrity and availability of the application are not affected. The EPSS score for this CVE is 0.23% with a percentile of 13.9, reflecting a low predicted likelihood of exploitation.

Root Cause

Oracle has not publicly disclosed the specific root cause. Based on the advisory metadata, the flaw permits an authenticated low-privileged user to access information they should not be authorized to read, which aligns with an information disclosure or broken access control pattern within the PJM Command Center module.

Attack Vector

The attack vector is network-based over HTTP. The attacker must already possess valid low-privileged credentials to the Oracle E-Business Suite deployment. After authenticating, the attacker issues crafted requests to the PJM Command Center endpoints to retrieve unauthorized data. No user interaction is required, and the scope is unchanged.

No public proof-of-concept or exploit code is available. Refer to the Oracle Security Alert July 2026 for vendor-published technical details.

Detection Methods for CVE-2026-60339

Indicators of Compromise

  • Unexpected HTTP requests to PJM Command Center endpoints originating from low-privileged user accounts.
  • Anomalous data export or query volumes from Oracle Project Manufacturing modules.
  • Access to Project Manufacturing data by user accounts that do not typically interact with the module.

Detection Strategies

  • Enable and review Oracle E-Business Suite audit logs, focusing on the Project Manufacturing and PJM Command Center pages.
  • Correlate authentication events with subsequent access to sensitive Project Manufacturing data sets to identify privilege misuse.
  • Baseline normal HTTP request patterns to E-Business Suite and alert on deviations tied to the affected component.

Monitoring Recommendations

  • Forward Oracle E-Business Suite application and web tier logs to a centralized SIEM for retention and correlation.
  • Monitor session activity for low-privileged accounts accessing high-value manufacturing data.
  • Track HTTP response sizes on PJM Command Center endpoints to detect bulk data retrieval attempts.

How to Mitigate CVE-2026-60339

Immediate Actions Required

  • Apply the security fixes published in the Oracle Critical Patch Update for July 2026 to affected Oracle E-Business Suite V16 environments.
  • Review user role assignments and remove unnecessary access to the Project Manufacturing product and PJM Command Center.
  • Restrict network exposure of the E-Business Suite web tier to trusted networks and authenticated VPN paths.

Patch Information

Oracle addressed CVE-2026-60339 in the July 2026 Critical Patch Update. Administrators should consult the Oracle Security Alert July 2026 advisory for the applicable patch identifiers and installation instructions for Oracle E-Business Suite V16.

Workarounds

  • Limit user account privileges within Oracle E-Business Suite to the minimum required, reducing the pool of accounts that could exploit the flaw.
  • Place a web application firewall in front of E-Business Suite to inspect and rate-limit traffic destined for PJM Command Center URLs.
  • Enforce strong authentication and session management on all E-Business Suite user accounts until patching is completed.
bash
# Configuration example
# Refer to Oracle's July 2026 Critical Patch Update documentation
# for exact patch application steps for Oracle E-Business Suite V16.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.