Summary
CVE-2026-61272 is a critical vulnerability in the Web Runtime SEC component of Oracle JD Edwards EnterpriseOne Tools. It allows an unauthenticated attacker with network access via HTTP to fully compromise the affected system, with high impact to confidentiality, integrity, and availability. Oracle rates this vulnerability 9.8 (CRITICAL) and disclosed it in the August 2026 Critical Patch Update.
Technical details
- Root cause: a flaw in the Web Runtime SEC component of JD Edwards EnterpriseOne Tools.
- Trigger conditions: exploitable remotely over HTTP without any authentication or user interaction.
- Attack vector: Network (AV:N), low attack complexity (AC:L), described by Oracle as "easily exploitable."
- Impact: successful exploitation can result in complete takeover of JD Edwards EnterpriseOne Tools, with high impact to confidentiality, integrity, and availability.
Affected software
- Oracle JD Edwards EnterpriseOne Tools, versions 9.2.0.0 through 9.2.26.4
Severity
- CVSS v3.1 Base Score: 9.8 (CRITICAL)
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Patch Update for JD Edwards EnterpriseOne Tools, upgrading beyond version 9.2.26.4.
- If patching cannot be applied immediately, restrict network exposure of JD Edwards EnterpriseOne Tools web components (e.g., limit access via firewall/VPN, avoid direct internet exposure) until the patch is deployed, and monitor for unusual HTTP requests to the platform.
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Loaded script URL:
/jde/share/js/e1.js - Raw response body:
E1URLFactory( - Page title:
JD Edwards

