HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46904Published Modified CNA oracle

CVE-2026-46904: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security)

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a critical-severity remote compromise vulnerability in Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2), specifically in the Enterprise Infrastructure Security component exposed over the JDENET protocol. The flaw is reachable over the network with no authentication required and no user interaction needed, making it trivially exploitable by any attacker who can reach the service. Successful exploitation results in full takeover of JD Edwards EnterpriseOne Tools, giving the attacker read, write, and denial-of-service control over the affected system. No fix versions have been published yet; HarborGuard is tracking this advisory and will surface a patched-image rebuild the moment Oracle releases one.

HarborGuard Coverage

Detection

Detection for CVE-2026-46904 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including internally built images that bundle JD Edwards EnterpriseOne Tools components at affected versions. Any image layer carrying a vulnerable version of the affected component is flagged automatically in the registry scan and in CI/CD pipeline checks.

Available
Triage

Triage is available with a CVSS 3.1 base score of 9.8 (Critical), and HarborGuard weights that score against each customer organization's compliance policy to determine urgency and routing. Findings are routed to the appropriate team inbox within the customer org based on image ownership and policy configuration, so the right engineers see the alert without manual triage overhead.

Available
Patch

Because no upstream fix has been published for this CVE, HarborGuard re-evaluates the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle ships a corrected version. In the interim, customers with compensating-control policies can use HarborGuard's network-policy isolation recommendations and egress-filtering guidance surfaced in the finding detail to reduce exposure of the JDENET service.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the JDENET service over the network; any host with TCP/IP connectivity to the exposed port is a viable attack origin.

  • AuthenticationNot required

    No credentials of any kind are needed; the vulnerability is exploitable by a completely unauthenticated attacker.

  • Victim interactionNot required

    The attack is entirely server-side and requires no action from any user or administrator on the target system.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, timing windows, or environmental preconditions to succeed.

Blast Radius

  • A successful attacker reads all data accessible to the JD Edwards EnterpriseOne Tools process, including configuration secrets, credentials, and business records stored or cached by the application.
  • The attacker writes to or modifies application data, configuration, and persisted records, enabling tampering with ERP transactions and system state.
  • The attacker can crash or render the JD Edwards EnterpriseOne Tools service unavailable, disrupting dependent business processes.
  • Full process-level takeover means the attacker can pivot to other systems reachable from the compromised host using the application's network identity and credentials.

How HarborGuard Handles This

Available on HarborGuard: continuous monitoring of this advisory is active, and any image containing JD Edwards EnterpriseOne Tools at versions 9.2.0.0 through 9.2.26.2 is flagged as critically vulnerable in scan results. Because Oracle has not yet published a fix, HarborGuard re-checks the advisory on every ingest cycle (typically every few minutes) and will make a patched-image rebuild available automatically as soon as an upstream fix is released. For customers with auto-remediation enabled, that rebuild will trigger a regression test run and a PR opened against affected workloads without manual intervention, subject to the customer's compliance policy. In the meantime, the finding detail surface in HarborGuard includes compensating-control guidance: consider applying Kubernetes network policies or firewall rules to restrict access to the JDENET port to only known trusted source IP ranges, and review whether the service needs to be internet-accessible at all. Customers should treat this as a zero-day-class finding and prioritize network isolation of exposed instances immediately.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / JD Edwards EnterpriseOne Tools
    ≤ 9.2.26.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References