Summary
CVE-2026-61265 is a vulnerability in the E1 IOT Orchestrator Security component of Oracle JD Edwards EnterpriseOne Orchestrator that allows an unauthenticated attacker with network access via TLS to compromise the Orchestrator. Oracle rates the issue HIGH severity (CVSS 3.1: 8.1), with successful exploitation potentially resulting in complete takeover of the affected system’s confidentiality, integrity, and availability.
Technical details
- Root cause: a flaw in the E1 IOT Orchestrator Security component of JD Edwards EnterpriseOne Orchestrator.
- Trigger conditions: exploitation requires no authentication and no user interaction, but Oracle rates attack complexity as High, meaning specific conditions or additional information/access beyond the network path must be present for a successful attack.
- Attack vector: network, reachable over TLS.
- Impact: if successfully exploited, results in high impact to confidentiality, integrity, and availability — described by Oracle as potential full compromise of the Orchestrator.
Affected software
- Oracle JD Edwards EnterpriseOne Orchestrator (E1 IOT Orchestrator Security component), versions 9.2.0.0 through 9.2.26.4.
Severity
- CVSS v3.1 Base Score: 8.1 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: apply the fix provided by Oracle in the August 2026 Critical Patch Update for all affected JD Edwards EnterpriseOne Tools/Orchestrator deployments running versions 9.2.0.0 through 9.2.26.4.
- If patching cannot be applied immediately: restrict network access to JD Edwards EnterpriseOne Orchestrator interfaces to trusted networks only, and monitor TLS-exposed Orchestrator endpoints for anomalous activity until the patch is deployed.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Raw response body:
E1URLFactory( - Page title:
JD Edwards - Loaded script URL:
/jde/share/js/e1.js

