CVE-2026-46903: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructure Security)
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is an authentication-bypass-adjacent privilege escalation vulnerability in the Business Logic Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools, versions 9.2.0.0 through 9.2.26.2. The flaw is reachable over the network via HTTP and requires only a low-privileged account, with no additional user interaction needed. Successful exploitation gives an attacker full control over the affected JD Edwards EnterpriseOne Tools instance, including complete read, write, and availability impact. No fix version has been published by Oracle; HarborGuard is tracking the advisory for patch availability.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that package JD Edwards EnterpriseOne Tools components.
AvailableHarborGuard is capable of scoring this finding at CVSS 8.8 (HIGH) and weighting it against each environment's compliance policy, then routing the alert to the appropriate team inbox within the customer organization.
AvailableBecause no upstream fix version has been published, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle ships a remediated release. In the meantime, customers can apply compensating controls through HarborGuard's policy engine to flag or block affected image versions from promotion to production.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the JD Edwards EnterpriseOne Tools HTTP endpoint over a network; the service must be accessible from the attacker's position.
- AuthenticationRequired
A valid low-privilege account is required; any authenticated user on the system can attempt the attack without needing administrative credentials.
- Victim interactionNot required
No victim interaction is needed; the attacker can carry out exploitation entirely without involving another user.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special conditions, race timing, or environmental configuration to succeed.
Blast Radius
- A successful attacker reads all data accessible to the JD Edwards EnterpriseOne Tools process, including business records, session tokens, and configuration credentials.
- A successful attacker modifies or deletes persisted business logic data, application configuration, and user records within the affected Tools instance.
- A successful attacker can crash or render the JD Edwards EnterpriseOne Tools service unavailable, disrupting dependent business processes.
- The combination of full confidentiality, integrity, and availability impact means the attacker achieves effective takeover of the application instance.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for this CVE, HarborGuard monitors the advisory on every feed-ingest cycle and will trigger a patched-image rebuild automatically once an upstream fix is released. For environments with auto-remediation enabled, that rebuild will be followed by a regression-test run and a PR opened against affected workloads. While no patch exists, customers can use HarborGuard's policy controls to enforce network-level isolation rules that restrict HTTP access to the JD Edwards EnterpriseOne Tools endpoint to only trusted source addresses, reducing the attack surface without requiring a code fix. Customers should also consider gating promotion of images containing affected versions (9.2.0.0 through 9.2.26.2) until Oracle publishes a remediated release.
- Oracle Corporation / JD Edwards EnterpriseOne Tools≤ 9.2.26.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H