PatchSiren cyber security CVE debrief
CVE-2026-60346 Oracle Corporation CVE debrief
A low severity vulnerability was found in JD Edwards EnterpriseOne Tools. This issue is related to the Interoperability Security component and affects version 9.2.26.3. The vulnerability is difficult to exploit and allows an unauthenticated attacker with network access via JDENET to potentially cause a partial denial of service (partial DOS). The CVSS 3.1 Base Score is 3.7, indicating a low severity impact primarily on availability. Organizations should be aware of this vulnerability and consider applying patches as recommended by the vendor.
- Vendor
- Oracle Corporation
- Product
- JD Edwards EnterpriseOne Tools
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-07-27
Who should care
Organizations using JD Edwards EnterpriseOne Tools version 9.2.26.3 should be aware of this vulnerability. Although it is difficult to exploit and has a low severity score, it could potentially lead to partial denial of service attacks if left unaddressed. Security teams and administrators responsible for JD Edwards EnterpriseOne Tools deployments should review the official advisory and consider applying patches or mitigations.
Technical summary
The CVE-2026-60346 vulnerability is in the Interoperability Security component of JD Edwards EnterpriseOne Tools version 9.2.26.3. It has a CVSS 3.1 score of 3.7, with an Attack Vector of Network (AV:N), Attack Complexity of High (AC:H), Privileges Required of None (PR:N), User Interaction of None (UI:N), and Scope of Unchanged (S:U). The impact is primarily on Availability (A:L). This vulnerability is difficult to exploit and allows an unauthenticated attacker with network access via JDENET to potentially cause a partial denial of service (partial DOS).
Defensive priority
Low priority, but recommended to apply patches as per vendor's security advisories and monitor for potential DOS attacks.
Recommended defensive actions
- Apply patches as recommended by the vendor
- Monitor network access to JD Edwards EnterpriseOne Tools
- Implement compensating controls to detect and prevent potential DOS attacks
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record was published on 2026-07-21T22:17:37.690Z and last modified on 2026-07-27T12:16:47.820Z. The NVD entry is currently Awaiting Analysis. Oracle's security alert page may contain additional information. The vulnerability affects version 9.2.26.3 of JD Edwards EnterpriseOne Tools, and its Interoperability Security component.
Official resources
-
CVE-2026-60346 CVE record
CVE.org
-
CVE-2026-60346 NVD detail
NVD
-
Source item URL
nvd_modified
- Source reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:37.690Z and has not been modified since then. The NVD entry is currently Awaiting Analysis.