Junglewise Threat Intelligence

CVE-2026-60626: Oracle JD Edwards EnterpriseOne Tools integrity vulnerability in Installation Security

CVE-2026-60626 · Severity: medium · CVSS 6 · Published 2026-07-21

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An attacker who already has high-level administrative access to the underlying server can exploit this flaw to modify or delete critical business data. This could lead to significant data integrity issues and potentially impact other connected systems beyond the JD Edwards environment.

Technical details

A vulnerability in the Installation Security component of Oracle JD Edwards EnterpriseOne Tools (specifically version 9.2.26.3) allows for unauthorized data manipulation. The flaw is categorized as easily exploitable but requires the attacker to have high-privileged access (PR:H) and local logon credentials to the infrastructure where the tools are executed. A successful exploit results in a scope change (S:C), meaning the impact can extend to other products or data sets accessible by the toolset. The primary impact is on data integrity, allowing for the unauthorized creation, deletion, or modification of critical information. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.26.3

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle in the July 2026 CPU.
  • 2026-07-21: advisory: NVD published the CVE record.

References

Related threats