Executive brief
A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to the total loss of business data confidentiality, unauthorized modification of records, and disruption of critical business operations.
Technical details
A vulnerability in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) is classified as Improper Access Control (CWE-284) and Missing Authentication (CWE-306). The flaw is easily exploitable via the JDENET protocol by an unauthenticated attacker with network access. Successful exploitation allows for a complete compromise of the JD Edwards EnterpriseOne Tools environment, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory