Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Business Logic Infra SEC component of Oracle JD Edwards EnterpriseOne Tools and permits a low‑privileged attacker who has network access via HTTP to perform unauthorized create, delete, or modify operations on critical data. The attack does not require authentication or can bypass existing authentication controls, and the demonstrated impact includes both confidentiality and integrity violations, as reflected by a CVSS 3.1 Base Score of 8.1. Successful exploitation allows an attacker to gain full data access or alter stored information, thereby compromising the integrity of the JD Edwards data store.

Affected Systems

Oracle JD Edwards EnterpriseOne Tools, versions 9.2.0.0 through 9.2.26.4, are affected. Network traffic to the HTTP interface must be able to reach the tool, and the vulnerability is exploitable by a low‑privileged user or script that can send HTTP requests to the system.

Risk and Exploitability

The high CVSS score combined with the absence of an EPSS score suggests a serious but currently unquantified risk. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed public exploits at the time of analysis. An attacker with minimal privileges and network connectivity can exploit the weakness; no special conditions or privileged credentials are required beyond basic network reachability. The exploitation path is straightforward: an unauthenticated or minimally authorized HTTP request triggers the vulnerable business logic, resulting in unauthorized data manipulation.

Generated by OpenCVE AI on August 21, 2026 at 11:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for CVE-2026-61268 to the JD Edwards EnterpriseOne Tools installation or upgrade to a later version that includes the fix.
  • Restrict HTTP access to JD Edwards EnterpriseOne Tools to trusted networks or specific users by configuring firewall rules or VPN access, ensuring that only authorized hosts can reach the vulnerable interface.
  • Review and tighten role‑based access controls so that privileged users are granted permissions to create, modify, or delete data within the JD Edwards environment.
  • Enable detailed logging and monitoring of CRUD operations on JD Edwards EnterpriseOne Tools to detect and alert on anomalous activity.

Generated by OpenCVE AI on August 21, 2026 at 11:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Weak Access Control in Oracle JD Edwards EnterpriseOne Tools
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infra SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T17:46:21.249Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61268

cve-icon Vulnrichment

Updated: 2026-08-21T15:29:36.943Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:57.090

Modified: 2026-08-28T14:17:26.717

Link: CVE-2026-61268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:00:11Z

Weaknesses