Junglewise Threat Intelligence

CVE-2026-46910: Oracle JD Edwards EnterpriseOne Tools improper access control in Infrastructure Security

CVE-2026-46910 · Severity: critical · CVSS 9.1 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software used to manage enterprise resource planning (ERP) applications. An unauthenticated attacker can exploit this flaw over the network to steal sensitive business data or cause a total system shutdown. This poses a significant risk to business continuity and the confidentiality of corporate records.

Technical details

This vulnerability affects the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools versions 9.2.0.0 through 9.2.26.2. It is classified as an improper access control or missing authentication issue (CWE-306, CWE-284) that is easily exploitable via HTTP without user interaction. A successful exploit allows a remote, unauthenticated attacker to gain unauthorized access to all data within the toolset or trigger a repeatable crash, resulting in a complete denial-of-service (DoS). Users are advised to consult the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0-9.2.26.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle released security alert cspujun2026.html

References

Related threats