Vulnerability in JD Edwards EnterpriseOne Tools by Oracle
CVE-2026-60347

3.6LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60347?

A vulnerability exists in Oracle JD Edwards EnterpriseOne Tools that allows a low-privileged attacker with legitimate logon access to compromise the software. This flaw enables unauthorized operations, including updates, inserts, or deletions of accessible data. Attackers may also partially disrupt the service, posing a security risk to enterprise infrastructure. It's crucial to take necessary precautions to mitigate potential exploits.

Affected Version(s)

JD Edwards EnterpriseOne Tools 9.2.26.3

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.