HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46891Published Modified CNA oracle

CVE-2026-46891: Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable)

Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Accounts Payable accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Accounts Payable accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Metrics

CVSS v3.1
8.1
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is an authorization/access-control vulnerability in the Accounts Payable component of Oracle JD Edwards EnterpriseOne version 9.2. An attacker with a low-privilege account can reach the vulnerable component over HTTP from the network and exploit it without any victim interaction. Successful exploitation gives the attacker full read access to all Accounts Payable data and the ability to create, modify, or delete critical records in that module. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds (NVD, Oracle advisories, and CNA sources) within minutes of publication and matched against customer images, including custom-built images that package JD Edwards EnterpriseOne components. Any image containing the affected 9.2 version surfaces in the HarborGuard findings dashboard automatically.

Available
Triage

HarborGuard scores this CVE at CVSS 8.1 (HIGH) and weights that score against each environment's compliance policy to determine priority and ownership routing. Findings are dispatched to the appropriate team inbox within the customer org based on configured policy rules, so the right engineers see the alert without manual triage.

Available
Patch

Because Oracle has not yet published a fix version, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. Until then, customers can apply compensating controls through HarborGuard's network-policy isolation recommendations to restrict HTTP access to the Accounts Payable component to authorized internal principals only.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the JD Edwards EnterpriseOne Accounts Payable service over the network via HTTP; the component is exposed at the network level (AV:N).

  • AuthenticationRequired

    The attacker must hold a valid low-privilege account on the system; unauthenticated access is not sufficient to trigger this vulnerability (PR:L).

  • Victim interactionNot required

    No user interaction or social engineering is needed; the attacker exploits the endpoint directly without involving another person (UI:N).

  • Attack complexityDetail

    Exploitation is straightforward and reliable under standard conditions, with no race conditions or special environmental setup required (AC:L).

Blast Radius

  • Reads all financial records accessible to the Accounts Payable module, including vendor details, invoice history, and payment data.
  • Creates, modifies, or deletes critical Accounts Payable records such as vendor accounts, invoices, and payment approvals.
  • Provides a foothold for fraudulent payment redirection or vendor-master manipulation within the ERP system.
  • Exposes sensitive financial data that may include bank account numbers, tax identifiers, and contract terms stored in the module.

How HarborGuard Handles This

Available on HarborGuard: because no fix version has been published by Oracle, HarborGuard monitors the advisory on every ingest cycle and will trigger a patched-image rebuild automatically when Oracle releases a remediated version. For environments with auto-remediation enabled, that rebuild will be followed by a regression test run and a PR opened against affected workloads, typically within 90 minutes of the fix version becoming available for high-severity issues. In the interim, HarborGuard surfaces this finding with a HIGH priority flag and supports compensating controls: customers can use HarborGuard's network-policy isolation recommendations to restrict HTTP access to the Accounts Payable endpoint to known internal IP ranges, and can apply role-scoping controls to reduce the number of low-privilege accounts that can reach the component. Customers whose compliance policy requires explicit sign-off before remediation will receive the finding in their approval queue rather than triggering an automatic PR.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / JD Edwards EnterpriseOne Accounts Payable
    9.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
References