Executive brief
A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure services used to manage enterprise resource planning (ERP) software. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to a total loss of data confidentiality, unauthorized modification of business records, and significant disruption to corporate operations.
Technical details
This vulnerability is classified as improper access control and missing authentication for a critical function (CWE-284, CWE-306) within the Enterprise Infrastructure Security component of JD Edwards EnterpriseOne Tools. The flaw is easily exploitable via HTTP without requiring any user interaction or prior authentication. A successful exploit allows a remote attacker to achieve a complete takeover of the affected JD Edwards EnterpriseOne Tools environment. Affected versions range from 9.2.0.0 through 9.2.26.2. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2
Timeline
- 2026-06-17: disclosed: Initial disclosure by Oracle
- 2026-06-17: advisory: NVD publication date