Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, the flaw appears to be an authentication bypass (CWE-287) and improper access control (CWE-284) – these CWE identifiers are inferred for analysis purposes – and permits unauthenticated attackers who can reach the service over HTTP to compromise the application, potentially taking full control. The repercussions include confidentiality, integrity, and availability loss, as reflected in the CVSS 3.1 base score of 9.8.

Affected Systems

Oracle JD Edwards EnterpriseOne Tools, versions 9.2.0.0 through 9.2.26.4, are affected according to the vendor’s advisory.

Risk and Exploitability

The CVSS score of 9.8 indicates critical severity. The EPSS score of 0.00358 indicates a very low but non‑zero probability of exploitation, yet the lack of required credentials and the ease of exploitation suggest a high likelihood of real‑world attacks. Although the vulnerability is not listed in the CISA KEV catalog, its remote takeover potential makes it a top‑priority risk for deployments exposed to the public or untrusted networks.

Generated by OpenCVE AI on August 21, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the August 2026 patch released by Oracle for JD Edwards EnterpriseOne Tools to eliminate the unauthenticated HTTP access flaw
  • Restrict inbound HTTP traffic to the JD Edwards instance, for example by limiting access to trusted IP ranges or by blocking the exposed port until the patch is applied
  • Continuously monitor system logs and network flows for signs of unauthorized access or exploitation attempts

Generated by OpenCVE AI on August 21, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Takeover via JD Edwards Web Runtime SEC
Weaknesses CWE-284
CWE-287

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T15:34:48.659Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61272

cve-icon Vulnrichment

Updated: 2026-08-21T15:34:39.464Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:57.340

Modified: 2026-08-27T18:51:25.250

Link: CVE-2026-61272

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T13:30:04Z

Weaknesses