Junglewise Threat Intelligence

CVE-2026-46892: Oracle JD Edwards EnterpriseOne Human Resources Management auth bypass

CVE-2026-46892 · Severity: critical · CVSS 9.1 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Human Resources Management. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle's JD Edwards EnterpriseOne Human Resources Management system, which is used by organizations to manage employee data and HR processes. An unauthorized person could use the internet to gain full access to sensitive personnel records without needing a username or password. This could lead to the theft of private employee information or the unauthorized modification and deletion of critical HR data.

Technical details

A vulnerability in the Human Resources component of Oracle JD Edwards EnterpriseOne Human Resources Management (version 9.2) is classified as Improper Access Control (CWE-284) and Missing Authentication for Critical Function (CWE-306). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. An attacker can achieve unauthorized creation, deletion, or modification of critical data, as well as complete unauthorized access to all data within the Human Resources Management module. The vulnerability has a CVSS 3.1 base score of 9.1, reflecting high confidentiality and integrity impacts with no impact on availability.

Affected products

  • Oracle JD Edwards EnterpriseOne Human Resources Management 9.2

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats