Junglewise Threat Intelligence

CVE-2026-46907: Oracle JD Edwards EnterpriseOne improper access control in Order Promising Integration

CVE-2026-46907 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle's JD Edwards EnterpriseOne Order Promising, a tool used by businesses to manage and commit to customer delivery dates. A low-privileged user can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive order data, disruption of supply chain operations, and potential unauthorized access to connected business systems.

Technical details

A vulnerability in the Order Promising Integration component of Oracle JD Edwards EnterpriseOne Order Promising (version 9.2) is classified as Improper Access Control (CWE-284). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. A successful exploit results in a 'scope change' (S:C), meaning the attacker can impact components beyond the immediate JD Edwards environment. This can lead to a total compromise of confidentiality, integrity, and availability, effectively allowing a complete takeover of the application. Oracle has addressed this in their June 2026 security update.

Affected products

  • Oracle JD Edwards EnterpriseOne Order Promising 9.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References