Security Vulnerability in JD Edwards EnterpriseOne Orchestrator from Oracle
CVE-2026-61265
8.1HIGH
Key Information:
- Vendor
Oracle
- Vendor
- CVE Published:
- 18 August 2026
What is CVE-2026-61265?
A vulnerability exists in the JD Edwards EnterpriseOne Orchestrator component, allowing an unauthenticated attacker with network access via TLS to potentially compromise the system. This flaw could enable an attacker to gain unauthorized control over the JD Edwards EnterpriseOne Orchestrator, posing significant risks to the confidentiality, integrity, and availability of the affected application.
Affected Version(s)
JD Edwards EnterpriseOne Orchestrator 9.2.0.0 <= 9.2.26.4