Junglewise Threat Intelligence

CVE-2026-46881: Oracle JD Edwards EnterpriseOne Tools improper access control in Enterprise Infrastructure Security

CVE-2026-46881 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to a total loss of data confidentiality, unauthorized modification of business records, and significant operational downtime.

Technical details

A vulnerability in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) is classified as Improper Access Control (CWE-284). The flaw is accessible via the JDENET proprietary communication protocol. An unauthenticated attacker with network access can exploit this vulnerability without any user interaction to compromise the environment. Successful exploitation results in a complete takeover of the JD Edwards EnterpriseOne Tools infrastructure, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 security alert for patching information.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD record published

References

Related threats