CVE-2026-60621: High severity Oracle JD Edwards EnterpriseOne Tools (Web Runtime Security) vulnerability
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). The supported version that is affected is 9.2.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60621?
The severity of CVE-2026-60621 is rated high, with a score of 8.1.
How do I fix CVE-2026-60621?
To mitigate CVE-2026-60621, it is recommended to upgrade Oracle JD Edwards EnterpriseOne Tools to version 9.2.26.4 or later.
Who can exploit CVE-2026-60621?
CVE-2026-60621 can be exploited by unauthenticated attackers with network access via HTTP.
What components are affected by CVE-2026-60621?
CVE-2026-60621 affects the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards, specifically Web Runtime Security.
What is the potential impact of CVE-2026-60621?
CVE-2026-60621 allows an unauthenticated attacker to compromise JD Edwards EnterpriseOne, potentially leading to high confidentiality, integrity, and availability risks.