Executive brief
A vulnerability exists in Oracle's JD Edwards EnterpriseOne CRM Foundation, a suite used by businesses to manage customer relationships and sales data. An attacker with basic user access to the network could exploit this flaw to take full control of the CRM system. This could lead to the theft of sensitive customer information, unauthorized modification of business records, or a complete shutdown of CRM operations.
Technical details
A high-severity vulnerability exists in the CRM Foundation component of Oracle JD Edwards EnterpriseOne version 9.2. The flaw is accessible via the JDENET proprietary communication protocol. While the attack complexity is rated as high, a successful exploit by a low-privileged attacker can result in a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle JD Edwards EnterpriseOne CRM Foundation 9.2
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory