CVE-2026-61272 – Oracle JD Edwards EnterpriseOne Tools
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“An unauthenticated network attacker can fully compromise affected EnterpriseOne Tools environments.”
Oracle addresses a Critical vulnerability in the Web Runtime SEC component of JD Edwards EnterpriseOne Tools. CVE-2026-61272 is remotely exploitable over HTTP without authentication and can result in high confidentiality, integrity, and availability impact. Affected versions include 9.2.0.0 through 9.2.26.4. The CVSS score is 9.8, which is Critical severity.
The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
Key Details
- Affected Product
- Oracle Jd Edwards Enterpriseone Tools
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-284
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.