Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The JD Edwards EnterpriseOne Tools installation component contains a flaw that permits a low‑privileged attacker with network access to send crafted HTTP requests, resulting in total compromise of the tool. The flaw provides full confidentiality, integrity, and availability loss, and a CVSS 3.1 base score of 8.8 highlights its serious capital. The vulnerability is rooted in inadequate access control, allowing takeover by an attacker who does not require elevated privileges. Affecting only the installation process, the weakness can be leveraged from any externally reachable point without additional authentication or user interaction. Successful exploitation would grant the attacker full control over the JD Edwards EnterpriseOne Tools instance, enabling arbitrary configuration changes, data exfiltration, or service disruption. Risk assessment shows a high likelihood of exploitation in environments where the tool is exposed to the internet. EPSS information is unavailable, but the combination of a high CVSS score, low attack complexity, and lack of privileged access suggests that a competent attacker could weaponize this flaw rapidly. The vulnerability is not listed in the CISA KEV catalog, which does not diminish the need for urgent remediation.

Affected Systems

Affected systems are Oracle Corporation's JD Edwards EnterpriseOne Tools, specifically the Installation Security component for versions 9.2.0.0 through 9.2.26.4. The vulnerability impacts the installation process of these releases and is not present in any later patches beyond 9.2.26.4.

Risk and Exploitability

The vulnerability scores a CVSS 3.1 base of 8.8, with high impact on confidentiality, integrity, and availability. The EPSS score is not available, indicating that no current exploitation data is reported; however, the low attack complexity and lack of privileged access suggest the risk remains high for exposed environments. The vulnerability is not listed in the CISA KEV catalog, so there is no known exploitation but that does not diminish the need for rapid patching. The attack vector is network-based over HTTP, with an attacker only needing to send crafted requests from an external host.

Generated by OpenCVE AI on August 21, 2026 at 11:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a version beyond 9.2.26.4 provided in the August 2026 security alert
  • Restrict inbound HTTP traffic to the JD Edwards EnterpriseOne Tools installation server to a trusted IP range and employ network segmentation to isolate it from the public network
  • Revoke or remove any non‑essential low‑privilege accounts that can reach the installation endpoint, ensuring that only authorized personnel have access

Generated by OpenCVE AI on August 21, 2026 at 11:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Title JD Edwards EnterpriseOne Tools Installation Component Remote Exploitation
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-21T15:36:07.439Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61273

cve-icon Vulnrichment

Updated: 2026-08-21T15:35:59.512Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:57.453

Modified: 2026-08-28T14:13:50.430

Link: CVE-2026-61273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:00:11Z

Weaknesses