CVE-2026-60626: Medium severity Oracle JD Edwards EnterpriseOne Tools vulnerability
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). The supported version that is affected is 9.2.26.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-60626?
The severity of CVE-2026-60626 is rated as medium with a score of 6.
Who is affected by CVE-2026-60626?
CVE-2026-60626 affects users of Oracle JD Edwards EnterpriseOne Tools, specifically version 9.2.26.3.
How can I mitigate CVE-2026-60626?
Mitigation for CVE-2026-60626 involves applying security patches and updates provided by Oracle.
Is CVE-2026-60626 easily exploitable?
Yes, CVE-2026-60626 is considered easily exploitable by a high privileged attacker with logon access to the infrastructure.
What component does CVE-2026-60626 affect in Oracle JD Edwards?
CVE-2026-60626 affects the Installation Security component of the JD Edwards EnterpriseOne Tools product.