Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Web Runtime Security component of Oracle JD Edwards EnterpriseOne Tools permits an unauthenticated attacker who can reach the system via standard HTTP to take full control of the Tools installation. This weakness is classified as CWE-306, indicating missing authentication checks. The flaw allows the attacker to gain unrestricted access, resulting in potential disclosure, modification, or destruction of data as it compromises the entire system. The impact is severe, touching confidentiality, integrity, and availability and effectively enabling a system takeover.

Affected Systems

Oracle JD Edwards EnterpriseOne Tools version 9.2.26.3 is affected. The description indicates that only this exact supported release contains the flaw; other versions are not listed as vulnerable. Users running this version should verify their deployment and ensure it is not exposed to the public internet.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 classifies the flaw as high severity, while the EPSS score of less than 1% suggests currently a very low, but non‑zero probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog, indicating no confirmed exploitation in the public domain yet. The attack vector is inferred to be network‑based, requiring only HTTP access and no authentication, and the difficulty is considered high for successful exploitation.

Generated by OpenCVE AI on August 5, 2026 at 01:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle‑issued security patch or upgrade to a JD Edwards EnterpriseOne Tools release that addresses this flaw.
  • Configure the web server to restrict HTTP access to the Tools installation to trusted users or IP ranges only.
  • Monitor application logs for anomalous authentication attempts and implement web‑application firewall rules to block known exploitation patterns.

Generated by OpenCVE AI on August 5, 2026 at 01:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated JD Edwards EnterpriseOne Tools Remote Takeover via Web Runtime Security

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows System Takeover in JD Edwards EnterpriseOne Tools
Weaknesses CWE-284
CWE-285
CWE-287

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows System Takeover in JD Edwards EnterpriseOne Tools
Weaknesses CWE-284
CWE-285
CWE-287

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP‑Based Compromise in JD Edwards EnterpriseOne Tools Web Runtime
Weaknesses CWE-284
CWE-287

Thu, 23 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP‑Based Compromise in JD Edwards EnterpriseOne Tools Web Runtime
Weaknesses CWE-284
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.26.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T18:20:54.249Z

Reserved: 2026-07-08T15:51:40.548Z

Link: CVE-2026-60621

cve-icon Vulnrichment

Updated: 2026-07-29T18:20:49.563Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:02.593

Modified: 2026-08-05T12:45:13.840

Link: CVE-2026-60621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function