HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46905Published Modified CNA oracle

CVE-2026-46905: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security)

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An authentication bypass (or equivalent critical security flaw) in the Web Runtime Security component of Oracle JD Edwards EnterpriseOne Tools allows an unauthenticated attacker with HTTP network access to fully compromise the affected system. The vulnerability is reachable over the network with no credentials and no user interaction required, making it trivially exploitable at scale. Successful exploitation gives the attacker complete control over the JD Edwards EnterpriseOne Tools instance, including full read, write, and availability impact. No fix version has been published yet; HarborGuard tracks the upstream Oracle advisory and will surface a patched-image rebuild the moment one becomes available.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds (including Oracle security advisories) within minutes of publication and matched against all customer images, including custom-built images derived from affected JD Edwards base layers. Any image carrying a JD Edwards EnterpriseOne Tools version between 9.2.0.0 and 9.2.26.2 is flagged immediately on scan.

Available
Triage

HarborGuard scores this CVE at CVSS 9.8 (Critical) and surfaces it at the top of each affected environment's vulnerability queue. Per-environment compliance policy weighting is applied automatically, and routing rules direct the finding to the appropriate team inbox within each customer organization based on image ownership and policy configuration.

Available
Patch

No upstream fix has been published for this CVE. HarborGuard re-evaluates the Oracle advisory on every ingest cycle and will make a patched-image rebuild available to affected environments the moment Oracle ships a corrected version. Where compliance policy permits, customers with auto-remediation enabled will receive an automatic rebuilt image, regression-test run, and a pull request opened against affected workloads without manual intervention.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must be able to reach the JD Edwards EnterpriseOne Tools HTTP service over the network; any internet- or intranet-exposed instance is directly in scope.

  • AuthenticationNot required

    No credentials of any kind are needed; the vulnerability is exploitable by a completely anonymous attacker.

  • Victim interactionNot required

    The attacker does not need to trick or involve any user; the exploit works entirely server-side.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and repeatable with no dependency on race conditions, specific memory layout, or other variable environmental factors.

Blast Radius

  • The attacker achieves full takeover of the JD Edwards EnterpriseOne Tools instance, gaining the ability to read all data the application can access, including financial records, supply chain data, and user credentials stored or processed by the ERP platform.
  • The attacker can modify or delete persisted application data, including business transactions, configuration, and user account information.
  • The attacker can crash or render the JD Edwards EnterpriseOne Tools service unavailable, disrupting ERP operations and dependent business processes.
  • With full system-level compromise, the attacker may use the host as a pivot point to reach adjacent internal systems that trust the ERP server.

How HarborGuard Handles This

Available on HarborGuard: this Critical-severity CVE (CVSS 9.8) is ingested and matched against customer images within minutes of advisory publication, with no manual intervention needed to trigger scanning. Because Oracle has not yet released a fix for affected versions (9.2.0.0 through 9.2.26.2), HarborGuard re-checks the advisory on every ingest cycle and will automatically trigger a patched-image rebuild and, for customers with auto-remediation enabled, open a PR against affected workloads the moment a corrected version is published upstream. In the interim, compensating controls available through HarborGuard policy enforcement include network-policy isolation to restrict inbound HTTP access to the JD Edwards Tools service to known trusted IP ranges, egress filtering to limit lateral movement from a compromised host, and alert escalation rules to route this finding to on-call security staff given the severity and absence of a patch. Customers are strongly advised to apply network-layer access controls immediately while awaiting an upstream fix.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / JD Edwards EnterpriseOne Tools
    ≤ 9.2.26.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References