Security Flaw in Oracle JD Edwards EnterpriseOne Tools Web Runtime Component
CVE-2026-61272

9.8CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-61272?

A serious vulnerability exists in the Web Runtime component of Oracle's JD Edwards EnterpriseOne Tools. This flaw allows unauthenticated attackers with network access via HTTP to compromise the affected systems. Successful exploitation could lead to complete control over JD Edwards EnterpriseOne Tools, impacting the confidentiality, integrity, and availability of the system.

Affected Version(s)

JD Edwards EnterpriseOne Tools 9.2.0.0 <= 9.2.26.4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.