HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46878Published Modified CNA oracle

CVE-2026-46878: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security)

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a critical-severity authentication bypass and full-system takeover vulnerability in Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2), specifically in the Enterprise Infrastructure Security component. An unauthenticated attacker with network access to the JDENET protocol interface can reach the vulnerable service without any credentials or victim interaction. Successful exploitation results in a complete takeover of the EnterpriseOne Tools instance, including full read, write, and availability impact. No fix version has been published; HarborGuard is tracking the advisory for patch availability.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: CVE-2026-46878 is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images, including custom-built images that bundle JD Edwards EnterpriseOne Tools components. Any image found running an affected version (9.2.0.0 through 9.2.26.2) is flagged automatically in the pipeline scan results.

Available
Triage

HarborGuard scores this CVE at 9.8 CRITICAL using the published CVSS v3.1 vector and weights findings against each customer organization's compliance policy, escalating appropriately for environments where unauthenticated network-reachable components are classified as high-exposure assets. Triage results are routed to the inbox or ticket queue configured for the relevant team within each customer org.

Available
Patch

Because no upstream fix version has been published for CVE-2026-46878, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle ships a corrective release. In the interim, HarborGuard surfaces compensating-control recommendations, including network-policy isolation to restrict JDENET port access and egress filtering, so teams can act before a patch arrives.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the vulnerable JDENET service over the network; any host with network access to the exposed port can attempt exploitation.

  • AuthenticationNot required

    No credentials of any kind are needed; the vulnerability is exploitable by a fully unauthenticated attacker.

  • Victim interactionNot required

    No action from any user or administrator is required to trigger the vulnerability.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory-layout knowledge, or environmental prerequisites.

Blast Radius

  • A successful attacker reads all data accessible to the EnterpriseOne Tools service, including configuration secrets, stored credentials, and any business records the application holds.
  • The attacker writes to or modifies persisted application data, configuration, and any database rows the service has access to.
  • The attacker crashes or fully disrupts the EnterpriseOne Tools service, denying access to all users depending on it.
  • The combination of full confidentiality, integrity, and availability impact constitutes a complete takeover of the affected EnterpriseOne Tools instance.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46878, the platform monitors the advisory on every ingest cycle and will automatically make a patched-image rebuild available the moment an upstream fix is released. For customers who opt into auto-remediation, that rebuild will trigger a regression test run and a PR opened against affected workloads without manual intervention. While no patch exists, HarborGuard surfaces actionable compensating controls for affected images: network-policy rules that restrict inbound access to the JDENET port to known-trusted sources, egress filtering to limit lateral movement if a container is compromised, and flagging of any pipeline stage that promotes an affected image to a production registry. Customers with strict compliance policies can configure HarborGuard to block promotion of images containing affected EnterpriseOne Tools versions until the upstream fix is confirmed ingested.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / JD Edwards EnterpriseOne Tools
    ≤ 9.2.26.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References