A critical (CVSS 9.9) vulnerability in Oracle JD Edwards EnterpriseOne Tools allows a low-privileged, network-based attacker to fully take over the product and impact adjacent systems.
What Is It
CVE-2026-60627 is a critical vulnerability in the Installation Security component of Oracle JD Edwards EnterpriseOne Tools. Oracle describes it as easily exploitable: a low-privileged attacker with network access over HTTP can compromise the product. No user interaction is required. Because the vulnerability carries a scope change, successful exploitation can significantly impact additional products beyond JD Edwards itself, ultimately resulting in complete takeover of JD Edwards EnterpriseOne Tools.
Why It Matters
The vulnerability holds a CVSS 3.1 base score of 9.9 (Critical) with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. It scores High across confidentiality, integrity, and availability, meaning an attacker can read data, alter it, and disrupt operations. Low attack complexity, network reach, and no required user interaction make this an attractive target. The scope change (S:C) is especially significant; an attacker who compromises this component can pivot to affect other connected products, widening the blast radius across an enterprise environment.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: JD Edwards EnterpriseOne Tools
- Component: Installation Security
- Affected version: 9.2.26.3 (the supported version identified as affected)
Patch Status
This CVE was published by Oracle as part of its July 2026 Critical Patch Update (CPU). Organizations running JD Edwards EnterpriseOne Tools should consult the Oracle July 2026 CPU advisory and apply the corresponding fixes. No CISA KEV entry was supplied for this CVE, so there is no confirmation of active exploitation in the provided source material.