HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46910Published Modified CNA oracle

CVE-2026-46910: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security)

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).

Metrics

CVSS v3.1
9.1
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a critical-severity unauthenticated remote vulnerability in Oracle JD Edwards EnterpriseOne Tools (versions 9.2.0.0 through 9.2.26.2), affecting the Enterprise Infrastructure Security component. An attacker reachable over HTTP needs no credentials and no victim interaction to exploit it. Successful exploitation reads all data accessible to the EnterpriseOne Tools instance and crashes or hangs the service entirely. No fix version has been published; HarborGuard tracks the advisory for patch availability.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against customer images, including custom-built images that bundle JD Edwards EnterpriseOne Tools components. Any image found running an affected version (9.2.0.0 through 9.2.26.2) is flagged immediately in the registry and CI pipeline scan results.

Available
Triage

HarborGuard scores this CVE at 9.1 CRITICAL (CVSS v3.1) and weights it further against each environment's compliance policy, elevating findings that sit on internet-facing or regulated workloads. Routed alerts are directed to the relevant team inbox within each customer organization based on image ownership rules.

Available
Patch

Because no upstream fix version has been published, HarborGuard re-checks the Oracle advisory and NVD record on every ingest cycle and will make a patched-image rebuild available the moment Oracle publishes a remediated release. In the interim, customers with network-policy controls can use HarborGuard's compensating-control suggestions to isolate affected workloads while the advisory is monitored.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the EnterpriseOne Tools service over a network via HTTP; any host with HTTP access to the service can attempt exploitation.

  • AuthenticationNot required

    No credentials of any kind are required; the vulnerability is exploitable by a completely unauthenticated attacker.

  • Victim interactionNot required

    No user action is needed; the attacker sends requests directly to the service without any social-engineering step.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory-layout knowledge, or environmental prerequisites.

Blast Radius

  • Reads all data accessible to the JD Edwards EnterpriseOne Tools instance, including configuration data, credentials stored within the component, and any application data the service can reach.
  • Causes a complete denial of service by crashing or indefinitely hanging the EnterpriseOne Tools process, taking dependent business processes offline until the service is manually restarted.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46910, HarborGuard monitors the Oracle CPU advisory and NVD record on every ingest cycle. The moment a patched release is published, a rebuilt image at that version becomes available, and customers with auto-remediation enabled will automatically receive a regression-tested rebuild plus a pull request opened against affected workloads. While no patch exists, HarborGuard surfaces compensating-control recommendations alongside the finding: network-policy isolation to restrict HTTP access to EnterpriseOne Tools to known internal CIDRs only, egress filtering to limit the blast radius if the service is compromised, and flagging the workload for expedited review in environments where the service is internet-exposed. For environments with auto-remediation enabled, median time from CVE publication to a merged patch PR for critical-severity issues is around 90 minutes once an upstream fix is available.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / JD Edwards EnterpriseOne Tools
    ≤ 9.2.26.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
References