Junglewise Threat Intelligence

CVE-2026-46891: Oracle JD Edwards EnterpriseOne improper access control in Accounts Payable

CVE-2026-46891 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle's JD Edwards EnterpriseOne Accounts Payable module, which is used by organizations to manage vendor invoices and payments. An attacker with low-level user access can exploit this flaw to view, modify, or delete sensitive financial data. This could lead to significant financial disruption, unauthorized payment manipulation, or the exposure of confidential corporate records.

Technical details

An improper access control vulnerability (CWE-284) exists in the Accounts Payable component of Oracle JD Edwards EnterpriseOne version 9.2. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. An attacker can bypass intended restrictions to gain unauthorized access to critical data, enabling the creation, deletion, or modification of all accessible data within the Accounts Payable module. The vulnerability impacts confidentiality and integrity but does not affect service availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation details.

Affected products

  • Oracle JD Edwards EnterpriseOne Accounts Payable 9.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats