Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in JD Edwards EnterpriseOne Tools’ Installation Security and can be exploited by a low‑privileged attacker with network access to the application over HTTP. Successful exploitation allows the attacker to fully take over the JD Edwards EnterpriseOne Tools instance, resulting in loss of confidentiality, integrity and availability of the system, and possibly affecting other connected JD Edwards products due to the scope change.

Affected Systems

Oracle Corporation’s JD Edwards EnterpriseOne Tools, version 9.2.26.3. The issue may also impact additional JD Edwards products that interface with the compromised Tools installation.

Risk and Exploitability

The CVSS score of 9.9 indicates critical severity, and the EPSS score of less than 1% signifies a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be a remote HTTP request from an attacker with low privileges; the problem is readily exploitable thanks to the lack of proper access controls, and the scope change allows privilege escalation or cross‑product damage.

Generated by OpenCVE AI on August 2, 2026 at 21:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch that addresses the JD Edwards EnterpriseOne Tools installation security flaw for version 9.2.26.3 or later.
  • Restrict HTTP access to JD Edwards EnterpriseOne Tools by firewall or ACL to only trusted administrative hosts until the patch is applied.
  • Disable or block the installation service endpoints exposed over HTTP to mitigate the vulnerability while planning remediation.

Generated by OpenCVE AI on August 2, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title JD Edwards EnterpriseOne Tools Installation Security Flaw Enables Full System Takeover

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Remote Takeover via Installation Security Flaw in JD Edwards EnterpriseOne Tools
Weaknesses CWE-284

Wed, 29 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Remote Takeover via Installation Security Flaw in JD Edwards EnterpriseOne Tools
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.26.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T18:20:12.535Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60627

cve-icon Vulnrichment

Updated: 2026-07-29T18:20:09.857Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:45:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function