Executive brief
A critical vulnerability has been identified in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure services used to manage enterprise resource planning (ERP) software. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to a total compromise of business operations, including the theft of sensitive corporate data and the disruption of essential services.
Technical details
A vulnerability in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) is classified as Improper Access Control (CWE-284). The flaw is easily exploitable by an unauthenticated attacker with network access via the JDENET protocol. Successful exploitation allows the attacker to compromise the JD Edwards EnterpriseOne Tools environment completely, impacting confidentiality, integrity, and availability. The vulnerability has a CVSS 3.1 base score of 9.8, indicating it is highly automatable and requires no user interaction. Users are advised to refer to the Oracle June 2026 Security Alert for patching information.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released