Executive brief
Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software for managing enterprise resource planning (ERP) applications, contains a critical security flaw in its Web Runtime Security component. An unauthorized person can exploit this over the network to gain full access to sensitive business data or modify records without a valid login. This could lead to significant data breaches or unauthorized changes to financial and operational records across the organization.
Technical details
A vulnerability in the Web Runtime Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) stems from improper access control and missing authentication (CWE-284, CWE-306). The flaw is easily exploitable via HTTP by an unauthenticated attacker with network access. Due to a scope change (S:C), an exploit can impact products beyond the immediate component, potentially granting complete confidentiality impact (C:H) and partial integrity impact (I:L). Attackers can read all accessible data and perform unauthorized updates, inserts, or deletes on a subset of data. Users are advised to refer to the Oracle June 2026 Critical Patch Update for remediation.
Affected products
- Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released