Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
Published: 2026-07-21
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an instance of CWE-284 Improper Access Control in the installation security of JD Edwards EnterpriseOne Tools version 9.2.26.3. An attacker without authentication who gains access to the physical communication segment attached to the hardware can potentially compromise the application. The exploitation requires an additional human interaction beyond the attacker and is difficult; if achieved, it allows the attacker to update, insert, or delete data and read portions of data that should be protected, thereby undermining confidentiality and integrity.

Affected Systems

Oracle Corporation’s JD Edwards EnterpriseOne Tools product, version 9.2.26.3, is affected; no other versions are listed as vulnerable.

Risk and Exploitability

The CVSS base score of 3.7 indicates low impact on confidentiality and integrity, and the EPSS score of less than 1 % reflects a very low probability of exploitation. The flaw is not included in the CISA KEV catalog and is limited to a local physical access scenario. While the overall risk is confined to personnel with physical access, achieving the exploit still requires human interaction beyond the attacker, and the potential for unauthorized data modification warrants timely remediation.

Generated by OpenCVE AI on August 5, 2026 at 01:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle July 2026 CPU update that contains the fix for JD Edwards EnterpriseOne Tools 9.2.26.3.
  • Restrict physical access to the servers running JD Edwards EnterpriseOne Tools and ensure only authorized personnel can use the adjacent communication segment.
  • Segregate the JD Edwards host network from other systems and monitor the physical communication segment for unusual traffic or configuration changes.

Generated by OpenCVE AI on August 5, 2026 at 01:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title JD Edwards EnterpriseOne Tools Installation Security Vulnerability with Physical Access

Sun, 02 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Physical Access Vulnerability in JD Edwards EnterpriseOne Tools Enables Unauthorized Data Modification

Mon, 27 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Physical Access Vulnerability in JD Edwards EnterpriseOne Tools Enables Unauthorized Data Modification
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:9.2.26.3:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T12:37:26.558Z

Reserved: 2026-07-08T15:51:40.549Z

Link: CVE-2026-60628

cve-icon Vulnrichment

Updated: 2026-07-27T12:37:22.824Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T02:00:12Z

Weaknesses