Junglewise Threat Intelligence

CVE-2026-46906: Oracle JD Edwards EnterpriseOne Tools access control bypass in Security component

CVE-2026-46906 · Severity: critical · CVSS 9.6 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An attacker with low-level access to the network can exploit this flaw to gain full control over sensitive business data, including the ability to view, modify, or delete critical records. Because this component handles core security infrastructure, a successful attack could also compromise other integrated business systems and data.

Technical details

An improper access control vulnerability (CWE-284) exists in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. A successful exploit results in a scope change (S:C), meaning the attacker can move beyond the initial component to impact other parts of the JD Edwards ecosystem. This can lead to unauthorized creation, deletion, or modification of all accessible data, as well as complete confidentiality loss of critical information. Affected versions range from 9.2.0.0 through 9.2.26.2.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats