CVE-2026-60618General(oracle / jd_edwards_enterpriseone_procurement_and_subcontract_management)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the JD Edwards EnterpriseOne Procurement and Subcontract Management product of Oracle JD Edwards (component: Procurement). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Procurement and Subcontract Management. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Procurement and Subcontract Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • jd_edwards_enterpriseone_procurement_and_subcontract_management

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-06); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
jd_edwards_enterpriseone_procurement_and_subcontract_management

1 version affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-06: 1Mentions · 2026-08-09: 1Technical Details · 2026-08-09: 108-0608-09
Signal classification1 categories
General
2100.0%
Referenced assets1 URL
Full discourse2 posts
  • ゆぅさん@YY20424277
    General

    【3軸解説】「オラクルのJD Edwards EnterpriseOne Procurement and Subcontract Managementにおける重要な機能に対する認証の欠如に関する脆弱性(CVE-2026-60618)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効… ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post presents a high‑level overview of CVE‑2026‑60618 affecting Oracle JD Edwards, noting an authentication issue but providing no detail on exploits, patches, or active use.

    0001068
    839 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「オラクルのJD Edwards EnterpriseOne Procurement and Subcontract Managementにおける重要な機能に対する認証の欠如に関する脆弱性(CVE-2026-60618)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効… ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post provides a brief explanation of an authentication bypass vulnerability in Oracle JD Edwards and links to a free analysis tool, but it does not mention active exploitation, PoC, or patch details.

    0000065
    839 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apporaclejd_edwards_enterpriseone_procurement_and_subcontract_management9.2--

Explore more