Installation Security Vulnerability in JD Edwards EnterpriseOne Tools by Oracle
CVE-2026-60626

6MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60626?

The JD Edwards EnterpriseOne Tools product by Oracle contains a vulnerability in its installation security component. This flaw allows high-privileged attackers who log onto the infrastructure running JD Edwards EnterpriseOne Tools to gain control over the product. While primarily affecting the tools themselves, the potential impact can extend to other associated products, leading to significant security risks. Successful exploitation can enable unauthorized users to create, delete, or modify critical data across all accessible data within JD Edwards EnterpriseOne.

Affected Version(s)

JD Edwards EnterpriseOne Tools 9.2.26.3

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.