CVE-2026-60490

Oracle · JD Edwards EnterpriseOne CRM Foundation

A vulnerability in Oracle JD Edwards EnterpriseOne CRM Foundation allows a low privileged attacker with network access to compromise and potentially take over the application.

Executive summary

A critical vulnerability in Oracle JD Edwards EnterpriseOne CRM Foundation 9.2 permits unauthorized system takeover by authenticated attackers.

Vulnerability

This is an easily exploitable flaw in the CRM Foundation component. It allows an attacker with low privileges and network access via HTTP to execute unauthorized actions, effectively leading to a full compromise of the software.

Business impact

The CVSS score of 8.8 reflects the high potential for total system takeover. Successful exploitation could result in the unauthorized disclosure of sensitive CRM data, modification of business records, or a complete denial of service, causing significant operational disruption and loss of data integrity.

Remediation

Immediate Action: Apply the Oracle Critical Patch Update for July 2026 to address this vulnerability.

Proactive Monitoring: Review application access logs for unusual activity originating from low privileged accounts and monitor for suspicious HTTP traffic directed at the CRM Foundation component.

Compensating Controls: Deploy Web Application Firewall rules to detect and block malicious HTTP requests that attempt to leverage this flaw while the patch is being scheduled for deployment.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Given the high CVSS score and the potential for a complete system takeover, organizations must prioritize the application of the July 2026 Critical Patch Update. Administrators should verify their current versioning and initiate the patching cycle immediately to minimize the exposure window.