Junglewise Threat Intelligence

CVE-2026-46879: Oracle JD Edwards EnterpriseOne Tools auth bypass in Infrastructure Security

CVE-2026-46879 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to a total compromise of business operations, including the theft of sensitive corporate data and the disruption of essential services.

Technical details

A vulnerability in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) is classified as a missing authentication for a critical function (CWE-306). The flaw is easily exploitable via the JDENET protocol, allowing a remote, unauthenticated attacker with network access to compromise the system. Successful exploitation results in a complete takeover of the JD Edwards EnterpriseOne Tools environment, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 security alert for patching information.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats