PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-60336 Oracle CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:36.707Z and has not been modified since then. The CVE-2026-60336 vulnerability affects Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. It allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data. The vulnerability has a CVSS 3.1 Base Score of 5.7, indicating a medium severity level with Confidentiality and Integrity impacts. The CVSS Vector is (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).

Vendor
Oracle
Product
Project Manufacturing
CVSS
MEDIUM 5.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-21
Original CVE updated
2026-07-31
Advisory published
2026-07-21
Advisory updated
2026-07-31

Who should care

Users of Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. These users should be aware of the potential risks associated with this vulnerability, including unauthorized access and data manipulation. They should also review and implement the recommended actions to mitigate these risks, such as applying patches according to vendor recommendations, restricting access to the infrastructure, monitoring for suspicious activity, and implementing compensating controls.

Technical summary

The CVE-2026-60336 vulnerability affects Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. The vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data. CVSS 3.1 Base Score 5.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N).

Defensive priority

Apply patches according to vendor recommendations.

Recommended defensive actions

  • Apply patches according to vendor recommendations
  • Restrict access to the infrastructure where Oracle Project Manufacturing executes
  • Monitor for suspicious activity
  • Implement compensating controls
  • Inventory and verify affected systems

Evidence notes

The CVE-2026-60336 vulnerability affects Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center) version V16. The vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to compromise Oracle Project Manufacturing. Successful attacks can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Manufacturing accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Manufacturing accessible data.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:36.707Z and has not been modified since then.