SYS::ONLINE
Wasteland.
Briefs1481
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-60627 2026-07-21

CVE-2026-60627: Critical JD Edwards EnterpriseOne Tools Takeover Flaw

"A critical (CVSS 9.9) vulnerability in Oracle JD Edwards EnterpriseOne Tools allows a low-privileged, network-based attacker to fully take over the product and impact adjacent systems."

A critical (CVSS 9.9) vulnerability in Oracle JD Edwards EnterpriseOne Tools allows a low-privileged, network-based attacker to fully take over the product and impact adjacent systems.

What Is It

CVE-2026-60627 is a critical vulnerability in the Installation Security component of Oracle JD Edwards EnterpriseOne Tools. Oracle describes it as easily exploitable: a low-privileged attacker with network access over HTTP can compromise the product. No user interaction is required. Because the vulnerability carries a scope change, successful exploitation can significantly impact additional products beyond JD Edwards itself, ultimately resulting in complete takeover of JD Edwards EnterpriseOne Tools.

Why It Matters

The vulnerability holds a CVSS 3.1 base score of 9.9 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. It scores High across confidentiality, integrity, and availability, meaning an attacker can read data, alter it, and disrupt operations. Low attack complexity, network reach, and no required user interaction make this an attractive target. The scope change (S:C) is especially significant; an attacker who compromises this component can pivot to affect other connected products, widening the blast radius across an enterprise environment.

What's Vulnerable

Patch Status

This CVE was published by Oracle as part of its July 2026 Critical Patch Update (CPU). Organizations running JD Edwards EnterpriseOne Tools should consult the Oracle July 2026 CPU advisory and apply the corresponding fixes. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.

Sources