Executive brief
A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to a total loss of data confidentiality, unauthorized modification of business records, and significant operational downtime.
Technical details
A vulnerability in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) is classified as Improper Access Control (CWE-284). The flaw is accessible via the JDENET proprietary communication protocol. An unauthenticated attacker with network access can exploit this vulnerability without any user interaction to compromise the environment. Successful exploitation results in a complete takeover of the JD Edwards EnterpriseOne Tools infrastructure, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 security alert for patching information.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD record published