Unauthenticated Access Vulnerability in Oracle JD Edwards EnterpriseOne General Ledger
CVE-2026-60494

7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60494?

A vulnerability exists in Oracle JD Edwards EnterpriseOne General Ledger, specifically within the E1 Foundation component, affecting version 9.2. This flaw allows an unauthenticated attacker with network access via HTTP to exploit the system. Successful exploitation can lead to unauthorized actions such as causing the application to hang or crash, resulting in a denial of service (DoS) condition. Furthermore, attackers could gain unauthorized access to update, insert, delete, or read sensitive data within the General Ledger. These impacts raise significant concerns about data confidentiality, integrity, and availability.

Affected Version(s)

JD Edwards EnterpriseOne General Ledger 9.2

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.