Junglewise Threat Intelligence

CVE-2026-46912: Oracle JD Edwards EnterpriseOne Tools auth bypass in Web Runtime Security

CVE-2026-46912 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

Oracle JD Edwards EnterpriseOne Tools, a suite of infrastructure software for managing enterprise resource planning (ERP) applications, contains a critical security flaw in its Web Runtime Security component. An unauthorized person can exploit this over the network to gain full access to sensitive business data or modify records without a valid login. This could lead to significant data breaches or unauthorized changes to financial and operational records across the organization.

Technical details

A vulnerability in the Web Runtime Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) stems from improper access control and missing authentication (CWE-284, CWE-306). The flaw is easily exploitable via HTTP by an unauthenticated attacker with network access. Due to a scope change (S:C), an exploit can impact products beyond the immediate component, potentially granting complete confidentiality impact (C:H) and partial integrity impact (I:L). Attackers can read all accessible data and perform unauthorized updates, inserts, or deletes on a subset of data. Users are advised to refer to the Oracle June 2026 Critical Patch Update for remediation.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released

References

Related threats