CVE-2026-60489

Oracle · JD Edwards EnterpriseOne CRM Foundation

A vulnerability in the CRM Foundation component of Oracle JD Edwards EnterpriseOne allows low-privileged network attackers to achieve full system takeover.

Executive summary

A critical vulnerability in Oracle JD Edwards EnterpriseOne CRM Foundation allows authenticated attackers to gain complete control over the application.

Vulnerability

This vulnerability resides within the CRM Foundation component. It allows an attacker with low privileges and network access via HTTP to exploit the application, potentially resulting in a complete takeover of the product.

Business impact

With a CVSS score of 8.8, this flaw poses a significant risk to the integrity and availability of business-critical CRM data. Exploitation could lead to unauthorized access to customer records, financial information, and administrative functions, resulting in severe reputational and operational damage.

Remediation

Immediate Action: Apply the Oracle Critical Patch Update for July 2026 to all affected JD Edwards EnterpriseOne installations.

Proactive Monitoring: Monitor system logs for unusual queries or unauthorized attempts to access CRM Foundation modules by low-privileged user accounts.

Compensating Controls: Restrict access to the JD Edwards environment to trusted network segments and utilize robust multi-factor authentication to limit the impact of compromised user credentials.

Exploitation status

Public Exploit Available: No confirmed public exploit is available in our curated sources.

Analyst recommendation

Due to the potential for full system compromise, security teams should prioritize the application of the July 2026 Critical Patch Update. Ensuring that all instances of JD Edwards EnterpriseOne CRM Foundation are updated is essential to maintaining the security posture of the application.