Junglewise Threat Intelligence

CVE-2026-46909: Oracle JD Edwards EnterpriseOne Tools authentication bypass in Infrastructure Security

CVE-2026-46909 · Severity: critical · CVSS 9.8 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure services used to manage enterprise resource planning (ERP) software. An unauthenticated attacker can exploit this flaw over the network to gain full control of the system. This could lead to a total loss of data confidentiality, unauthorized modification of business records, and significant disruption to corporate operations.

Technical details

This vulnerability is classified as improper access control and missing authentication for a critical function (CWE-284, CWE-306) within the Enterprise Infrastructure Security component of JD Edwards EnterpriseOne Tools. The flaw is easily exploitable via HTTP without requiring any user interaction or prior authentication. A successful exploit allows a remote attacker to achieve a complete takeover of the affected JD Edwards EnterpriseOne Tools environment. Affected versions range from 9.2.0.0 through 9.2.26.2. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats