CVE-2026-61272: Critical severity Oracle JD Edwards EnterpriseOne Tools (Web Runtime SEC) vulnerability
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Deployments of Oracle JD Edwards EnterpriseOne Tools using the Web Runtime SEC component are affected if they run a supported version from 9.2.0.0 through 9.2.26.4 and are reachable over HTTP. The attack can be performed remotely over the network.
Does an attacker need credentials or user interaction to exploit it?
No. The vulnerability is described as easily exploitable by an unauthenticated attacker with network access via HTTP, and it requires no user interaction.
What could a successful attack allow?
A successful attack can result in takeover of JD Edwards EnterpriseOne Tools. It can affect confidentiality, integrity, and availability.