Junglewise Threat Intelligence

CVE-2026-46913: Oracle JD Edwards EnterpriseOne Tools access control bypass in Installation Security

CVE-2026-46913 · Severity: critical · CVSS 9.3 · Published 2026-06-17

Technologies: Oracle JD Edwards EnterpriseOne Tools. Vendors: Oracle.

Executive brief

A critical security flaw exists in Oracle's JD Edwards EnterpriseOne Tools, which provides the underlying infrastructure for JD Edwards business applications. An attacker with access to the server where this software is installed can completely take over the system, potentially gaining access to sensitive business data and impacting other connected services. This could lead to a total loss of confidentiality and operational disruption for organizations using affected versions.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Installation Security component of JD Edwards EnterpriseOne Tools. It is easily exploitable by an unauthenticated attacker who has logged onto the underlying infrastructure where the tools execute. The vulnerability is notable for its 'Scope Change' (S:C), meaning a successful exploit can impact components beyond the JD Edwards environment itself. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability (takeover) of the affected system. Affected versions range from 9.2.0.0 through 9.2.26.2.

Affected products

  • Oracle JD Edwards EnterpriseOne Tools 9.2.0.0 - 9.2.26.2

Timeline

  • 2026-06-17: advisory: Oracle published the security advisory.
  • 2026-06-17: disclosed: Vulnerability details made public via NVD.

References

Related threats