Junglewise Threat Intelligence

CVE-2026-46905: Oracle JD Edwards EnterpriseOne Tools authentication bypass in Web Runtime Security

CVE-2026-46905 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to the total compromise of business data, unauthorized operational changes, and significant service disruptions.

Technical details

A vulnerability in the Web Runtime Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) is classified as CWE-306 (Missing Authentication for Critical Function). The flaw is easily exploitable by an unauthenticated attacker with network access via HTTP. Successful exploitation allows the attacker to compromise the JD Edwards EnterpriseOne Tools environment, leading to a complete loss of confidentiality, integrity, and availability (CVSS 9.8). Oracle has addressed this in the June 2026 Critical Patch Update.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released

References

Related threats