CVE-2026-46906: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security)
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An authorization or access-control flaw in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2) is reachable over the network via HTTP and requires only a low-privileged account to trigger. The CVSS scope-change flag indicates the exploit can break out of the directly targeted component and affect other products in the environment. Successful exploitation gives an attacker full read access to all data the application can reach, as well as the ability to create, modify, or delete critical records. No fix version has been published by Oracle; HarborGuard is tracking the advisory and will make a patched-image rebuild available as soon as an upstream fix is released.
HarborGuard Coverage
Detection for CVE-2026-46906 is available across every HarborGuard environment: the CVE is ingested from upstream feeds, including Oracle's advisory channel, within minutes of publication and matched against all customer images in connected registries and CI pipelines, including custom-built images that layer JD Edwards EnterpriseOne Tools components.
AvailableHarborGuard scores this CVE at 9.6 Critical (CVSS v3.1) and weights it against each customer organization's compliance policy to determine priority and routing. Findings are surfaced to the team inbox or ticketing integration configured for the affected environment, ensuring the right engineers see the alert without manual triage.
AvailableBecause no fix version has been published, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle releases a remediated version. In the meantime, customers can apply compensating controls through HarborGuard's network-policy and egress-filtering recommendations visible on the advisory detail panel.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the JD Edwards EnterpriseOne Tools HTTP endpoint over a network connection; the service does not need to be internet-facing, but it must be accessible from the attacker's position.
- AuthenticationRequired
Any low-privilege account on the JD Edwards system is sufficient; no administrative rights are needed, but the attacker must have valid credentials.
- Victim interactionNot required
No victim action such as clicking a link or opening a file is needed; the attacker sends crafted HTTP requests directly to the service.
- Attack complexityDetail
Attack complexity is Low, meaning the exploit is reliable and requires no special race conditions, memory-layout knowledge, or other environmental prerequisites.
Blast Radius
- Reads all data accessible to the JD Edwards EnterpriseOne Tools application, including sensitive business records and credentials stored within the platform.
- Creates, modifies, or deletes critical data rows across JD Edwards modules reachable by the compromised component.
- Because the CVSS scope changes, the attacker can pivot to affect other products and services in the same environment that trust or share data with JD Edwards EnterpriseOne Tools.
How HarborGuard Handles This
Available on HarborGuard: this CVE is flagged Critical (9.6) and is matched against images in every connected registry and pipeline as soon as the advisory is ingested. Because Oracle has not yet published a fix, HarborGuard monitors the advisory on each ingest cycle and will trigger a patched-image rebuild and, for customers with auto-remediation enabled, a regression-test run and a PR against affected workloads the moment an upstream fix is released. While no patch exists, customers can use HarborGuard's compensating-control guidance to restrict network-policy rules so that only explicitly authorized services can reach the JD Edwards HTTP endpoint, apply egress filtering to limit lateral movement in the event of compromise, and use feature-flag or access-control overlays to reduce the pool of low-privileged accounts that can interact with the vulnerable component. HarborGuard will notify configured alert channels the moment the advisory status changes.
- Oracle Corporation / JD Edwards EnterpriseOne Tools≤ 9.2.26.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N