HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46881Published Modified CNA oracle

CVE-2026-46881: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security)

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a critical-severity unauthenticated remote compromise vulnerability in Oracle JD Edwards EnterpriseOne Tools (Enterprise Infrastructure Security component), affecting versions 9.2.0.0 through 9.2.26.2. An attacker with network access to the JDENET protocol endpoint needs no credentials and no victim interaction to exploit this flaw. Successful exploitation results in full takeover of the JD Edwards EnterpriseOne Tools environment, including complete loss of confidentiality, integrity, and availability. No fix versions have been published by Oracle at this time; HarborGuard is tracking the advisory for patch availability.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images, including custom-built images that bundle JD Edwards EnterpriseOne Tools components. Any image running an affected version (9.2.0.0 through 9.2.26.2) will surface a finding in the customer's scan results automatically.

Available
Triage

HarborGuard scores this finding at CVSS 9.8 (Critical) and weights it against each environment's configured compliance policy, escalating breach-of-threshold findings to the appropriate team inbox within each customer organization. Per-environment context such as internet-exposed registries or privileged workload labels is surfaced alongside the finding to support prioritization.

Available
Patch

Because no upstream fix has been published, HarborGuard re-checks the Oracle advisory and downstream feeds on every ingest cycle; a patched-image rebuild will become available automatically the moment Oracle ships a remediated version. In the meantime, customers with network-isolation or egress-filtering compensating controls configured in their compliance policy will see those controls flagged as applicable mitigations against this finding.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the target service over the network via the JDENET protocol; any host with network access to the exposed port is a viable attack origin.

  • AuthenticationNot required

    No credentials of any kind are needed; the vulnerability is exploitable by a completely unauthenticated attacker.

  • Victim interactionNot required

    No user action or social engineering is required; the attacker interacts directly with the service.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and imposes no special preconditions such as race conditions or specific memory layout requirements.

Blast Radius

  • A successful attacker reads all data accessible to the JD Edwards EnterpriseOne Tools process, including configuration secrets, credentials, and business records.
  • A successful attacker writes to or modifies persisted application data, configuration, and any database rows the Tools process can reach.
  • A successful attacker crashes or shuts down the JD Edwards EnterpriseOne Tools service, disrupting all dependent business processes.
  • Full process-level takeover means an attacker can pivot to other systems reachable from the compromised host using inherited network trust or stored credentials.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46881, the platform monitors the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers who opt into auto-remediation, that rebuild will trigger a regression test run and a PR opened against affected workloads without manual intervention. While no patch exists, recommended compensating controls include applying strict network policy to block unsolicited inbound access to JDENET ports, enabling egress filtering on hosts running EnterpriseOne Tools to limit lateral movement, and using feature-flag or deployment-config gating to take the component offline in environments where JDENET exposure is not operationally required. Customers whose compliance policy includes network-isolation rules will see those controls surfaced alongside the finding in the triage view.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / JD Edwards EnterpriseOne Tools
    ≤ 9.2.26.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References