Junglewise Threat Intelligence

CVE-2026-46911: Oracle JD Edwards EnterpriseOne access control bypass in Job Costing

CVE-2026-46911 · Severity: critical · CVSS 9.6 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle's JD Edwards EnterpriseOne Project Costing software, which is used by businesses to manage project finances and job costs. An attacker with basic user access can exploit this flaw over the network to gain full control over project data, including the ability to view, modify, or delete sensitive financial records. This breach could potentially spread to other connected Oracle systems, leading to significant operational disruption and data loss.

Technical details

This vulnerability is classified as Improper Access Control (CWE-284) within the Job Costing component of Oracle JD Edwards EnterpriseOne Project Costing version 9.2. It is easily exploitable by a low-privileged attacker with network access via the JDENET protocol. The flaw allows for a 'scope change' (CVSS S:C), meaning a successful exploit can impact components beyond the immediate security scope of the Project Costing product. Attackers can achieve unauthorized creation, deletion, or modification of all accessible data, as well as complete read access to critical information. Oracle has addressed this in the June 2026 Critical Patch Update.

Affected products

  • Oracle JD Edwards EnterpriseOne Project Costing 9.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released

References