PatchSiren cyber security CVE debrief
CVE-2026-60338 Oracle CVE debrief
The CVE-2026-60338 vulnerability affects Oracle Project Manufacturing V16, a component of Oracle E-Business Suite. This vulnerability is difficult to exploit and requires a low-privileged attacker with logon access to the infrastructure where Oracle Project Manufacturing executes. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle Project Manufacturing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Project Manufacturing. The CVSS 3.1 Base Score is 3.6, indicating a low severity. The vulnerability is categorized under Integrity and Availability impacts, with a CVSS Vector of (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).
- Vendor
- Oracle
- Product
- Project Manufacturing
- CVSS
- LOW 3.6
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-31
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-31
Who should care
Oracle Project Manufacturing users and administrators should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing system configurations, applying patches as recommended by Oracle, and monitoring system logs for potential suspicious activity. Additionally, security teams and vulnerability management teams should prioritize patching to prevent potential low-privileged attacks. Affected operators and platforms should also take note of this vulnerability and implement compensating controls to limit potential damage if patching is not immediately feasible. This vulnerability may impact various security teams, including those responsible for vulnerability management, incident response, and system security posture. Therefore, it is crucial for these teams to assess their exposure and take appropriate measures to mitigate the risk associated with this vulnerability. The affected product deployments should be reviewed to ensure they are properly secured, and owners should be assigned for follow-up actions. Compensating controls should be considered for exposed systems while remediation is scheduled and verified. Monitoring, detection, and logs for exposed assets should be checked for extra review, and exceptions should be tracked, with remediated assets retested and the item closed only after evidence is documented. Asset inventory and change management processes may also need to be reviewed to ensure that affected systems are properly accounted for and secured. Overall, a coordinated effort is required from various stakeholders to effectively manage and mitigate the risks associated with this vulnerability. Oracle Project Manufacturing V16 users must verify their system configurations and apply patches as recommended by Oracle to prevent potential attacks. Security teams should also consider implementing additional security measures, such as enhanced monitoring and incident response planning, to address the potential risks associated with this vulnerability. By taking these steps, organizations can help protect their systems and data from potential exploitation. The debrief provides an executive overview of the CVE-
Technical summary
The CVE-2026-60338 vulnerability affects Oracle Project Manufacturing V16 and allows low-privileged attackers with logon access to compromise the system, potentially leading to unauthorized data updates, inserts, or deletions, and partial denial of service. The CVSS 3.1 score is 3.6, indicating a low severity. The vulnerability is difficult to exploit and requires a low-privileged attacker with logon access to the infrastructure where Oracle Project Manufacturing executes.
Defensive priority
Oracle Project Manufacturing users should prioritize patching to prevent potential low-privileged attacks.
Recommended defensive actions
- Apply the Oracle patch as described in the vendor advisory
- Verify system configurations to ensure they are not vulnerable
- Monitor system logs for potential suspicious activity
- Implement compensating controls to limit potential damage
- Review system configurations to ensure they align with security best practices
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE-2026-60338 vulnerability affects Oracle Project Manufacturing V16 and allows low-privileged attackers with logon access to compromise the system, potentially leading to unauthorized data updates, inserts, or deletions, and partial denial of service. The CVSS 3.1 score is 3.6, indicating a low severity. Users should verify their system configurations and apply patches as recommended by Oracle.
Official resources
-
CVE-2026-60338 CVE record
CVE.org
-
CVE-2026-60338 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:36.920Z and has not been modified since then.