Executive brief
A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An unauthenticated attacker can exploit this flaw over the network to steal sensitive business data or cause a total system shutdown. This poses a significant risk to business continuity and the confidentiality of corporate records.
Technical details
This vulnerability affects the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools versions 9.2.0.0 through 9.2.26.2. It is classified as an improper access control or missing authentication issue (CWE-306, CWE-284) that is easily exploitable via HTTP without user interaction. A successful exploit allows a remote, unauthenticated attacker to gain unauthorized access to all data within the toolset or trigger a repeatable crash, resulting in a complete denial-of-service (DoS). Users are advised to consult the Oracle Critical Patch Update for June 2026 for remediation steps.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle released security alert cspujun2026.html