Security Flaw in JD Edwards EnterpriseOne Tools from Oracle
CVE-2026-60628

3.7LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60628?

The JD Edwards EnterpriseOne Tools from Oracle is exposed to a vulnerability that allows an unauthenticated attacker with physical access to the hardware to potentially exploit the system. This security flaw necessitates human interaction from a bystander for exploitation, making it complex to execute. If successfully attacked, unauthorized individuals could gain the ability to update, insert, or delete sensitive data within the JD Edwards environment, along with unauthorized read access to certain data. This vulnerability emphasizes the importance of physical security measures in addition to traditional cybersecurity protocols to safeguard sensitive information.

Affected Version(s)

JD Edwards EnterpriseOne Tools 9.2.26.3

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.