Junglewise Threat Intelligence

CVE-2026-60347: Oracle JD Edwards EnterpriseOne Tools data manipulation in Infrastructure Security

CVE-2026-60347 · Severity: low · CVSS 3.6 · Published 2026-07-21

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure components used to manage enterprise resource planning (ERP) software. An attacker who already has low-level access to the underlying server could potentially modify or delete certain business data and cause minor service disruptions. While the impact is limited to specific data and partial service availability, it represents a risk to the integrity of the enterprise environment.

Technical details

This vulnerability affects the Enterprise Infrastructure Security component of JD Edwards EnterpriseOne Tools version 9.2.26.3. It is classified as difficult to exploit (AC:H) and requires the attacker to have local logon credentials to the infrastructure where the software executes (AV:L). Successful exploitation allows a low-privileged user to perform unauthorized updates, insertions, or deletions of accessible data. Additionally, the flaw can be leveraged to cause a partial denial of service (DoS). The vulnerability does not allow for the unauthorized disclosure of information (Confidentiality is not impacted). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.26.3

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats