PatchSiren cyber security CVE debrief
CVE-2026-60336 Oracle CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:36.707Z and has not been modified since then. The CVE-2026-60336 vulnerability affects Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. It allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data. The vulnerability has a CVSS 3.1 Base Score of 5.7, indicating a medium severity level with Confidentiality and Integrity impacts. The CVSS Vector is (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).
- Vendor
- Oracle
- Product
- Project Manufacturing
- CVSS
- MEDIUM 5.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-31
Who should care
Users of Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. These users should be aware of the potential risks associated with this vulnerability, including unauthorized access and data manipulation. They should also review and implement the recommended actions to mitigate these risks, such as applying patches according to vendor recommendations, restricting access to the infrastructure, monitoring for suspicious activity, and implementing compensating controls.
Technical summary
The CVE-2026-60336 vulnerability affects Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. The vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).
Defensive priority
Apply patches according to vendor recommendations.
Recommended defensive actions
- Apply patches according to vendor recommendations
- Restrict access to the infrastructure where Oracle Project Manufacturing executes
- Monitor for suspicious activity
- Implement compensating controls
- Inventory and verify affected systems
Evidence notes
The CVE-2026-60336 vulnerability affects Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. The vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data.
Official resources
-
CVE-2026-60336 CVE record
CVE.org
-
CVE-2026-60336 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:36.707Z and has not been modified since then.