Junglewise Threat Intelligence

CVE-2026-46908: Oracle JD Edwards EnterpriseOne access control bypass in Accounts Payable

CVE-2026-46908 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle's JD Edwards EnterpriseOne Accounts Payable module, which is used by organizations to manage vendor invoices and payments. A low-privileged user can exploit this flaw over the network to gain full control of the application. This could lead to the unauthorized disclosure of sensitive financial data, fraudulent payment activity, or a complete disruption of the accounts payable process.

Technical details

This vulnerability (CWE-284) is located in the Accounts Payable component of Oracle JD Edwards EnterpriseOne version 9.2. It is classified as an improper access control issue that is easily exploitable via HTTP. An attacker with low-level privileges and network access can achieve a full compromise of the component. Notably, the vulnerability involves a 'scope change' (S:C), meaning a successful exploit can impact other components or products beyond the Accounts Payable module itself. This can result in a total loss of confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation details.

Affected products

  • Oracle JD Edwards EnterpriseOne Accounts Payable 9.2

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD entry published

References

Related threats