Junglewise Threat Intelligence

CVE-2026-46883: Oracle JD Edwards EnterpriseOne Tools access control bypass in JDENET

CVE-2026-46883 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to a total compromise of business operations, including the theft of sensitive corporate data and the disruption of essential financial or supply chain services.

Technical details

This vulnerability is classified as Improper Access Control (CWE-284) within the Enterprise Infrastructure Security component of JD Edwards EnterpriseOne Tools. The flaw is reachable via the JDENET proprietary communication protocol and does not require any user interaction or prior authentication. An attacker with network access to the JDENET port can exploit this vulnerability to achieve a complete takeover of the affected JD Edwards environment, impacting confidentiality, integrity, and availability. Affected versions range from 9.2.0.0 through 9.2.26.2. Users are advised to consult the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle published security alert cspujun2026.html

References

Related threats