Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N).
Published: 2026-07-21
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the installation security mechanism of Oracle JD Edwards EnterpriseOne Tools allows a high‑privileged attacker who can log onto the host where the tools run to create, delete, or modify critical data. The vulnerability is easily exploitable and the impact is restricted to integrity, as the attacker can alter any data accessible to the tools. This weakness reflects an improper access control flaw (CWE‑284). While the description limits the direct impact to JD Edwards EnterpriseOne Tools, the vulnerability can potentially change scope and affect additional downstream JD Edwards components.

Affected Systems

Oracle Corporation’s JD Edwards EnterpriseOne Tools version 9.2.26.3 is the only fully documented affected release. The issue is specific to the Installation Security component of the tools but may extend to other JD Edwards products, due to a scope change, if they share the same installation context or data store.

Risk and Exploitability

The CVSS v3.1 base score is 6.0, indicating a moderate severity with a focus on integrity. The CVSS vector indicates no (AV:L) and requires high privileges (PR:H), with no user interaction (UI:N). The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Given that the attack requires a local privileged account, the risk for an external adversary is low, but for internal or disgruntled employees the likelihood rises. Organizations should therefore consider that this can lead to significant data corruption if unaddressed.

Generated by OpenCVE AI on August 4, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for JD Edwards EnterpriseOne Tools that addresses the installation security flaw.
  • Limit installation‑time privileged accounts to only the minimal set of permissions required for deployment, avoiding the use of system administrators where possible.
  • Enforce strict auditing and monitoring of data modification operations performed by JD Edwards EnterpriseOne Tools to detect unauthorized changes early.

Generated by OpenCVE AI on August 4, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in JD Edwards EnterpriseOne Tools Enables Local Privileged Data Modification

Thu, 30 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in JD Edwards EnterpriseOne Tools Enables Local Privileged Data Modification

Tue, 28 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in JD Edwards EnterpriseOne Tools Enables Unauthorized Data Modification
Weaknesses CWE-269

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 26 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in JD Edwards EnterpriseOne Tools Enables Unauthorized Data Modification
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.26.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:36:41.787Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60626

cve-icon Vulnrichment

Updated: 2026-07-27T12:36:03.882Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:30:03Z

Weaknesses