Vulnerability in JD Edwards EnterpriseOne Procurement by Oracle
CVE-2026-60618
8.8HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 21 July 2026
What is CVE-2026-60618?
A vulnerability exists in Oracle's JD Edwards EnterpriseOne Procurement and Subcontract Management product, specifically affecting version 9.2. This issue can be exploited by low privileged attackers who have network access via HTTP, potentially leading to unauthorized control over the application. Successful exploitation of this vulnerability poses significant risks, including compromise of confidentiality, integrity, and availability of the affected system.
Affected Version(s)
JD Edwards EnterpriseOne Procurement and Subcontract Management 9.2