HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46912Published Modified CNA oracle

CVE-2026-46912: Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security)

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).

Metrics

CVSS v3.1
9.3
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is an authentication bypass and data-exposure vulnerability in the Web Runtime Security component of Oracle JD Edwards EnterpriseOne Tools, affecting versions 9.2.0.0 through 9.2.26.2. An unauthenticated attacker with network access over HTTP can exploit this remotely with no user interaction required, and the scope of impact extends beyond the directly targeted component. Successful exploitation gives the attacker full read access to all data accessible by JD Edwards EnterpriseOne Tools and limited write access to insert, update, or delete some of that data. No fix version has been published yet; HarborGuard tracks this advisory and will make a patched-image rebuild available the moment Oracle ships an upstream fix.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle JD Edwards EnterpriseOne Tools components.

Available
Triage

HarborGuard scores this CVE at 9.3 CRITICAL using the published CVSS v3.1 vector and weights it against each environment's compliance policy to determine urgency and routing. Triage findings are surfaced to the appropriate team inbox within each customer organization based on affected image ownership and policy configuration.

Available
Patch

Because no upstream fix version has been published for this CVE, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment a fix is released. In the interim, customers can use HarborGuard's policy controls to flag or block deployment of images containing affected versions of JD Edwards EnterpriseOne Tools (9.2.0.0 through 9.2.26.2).

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the JD Edwards EnterpriseOne Tools web interface over the network via HTTP; no local or physical access is needed.

  • AuthenticationNot required

    No credentials or account of any privilege level are required to trigger this vulnerability.

  • Victim interactionNot required

    The attacker does not need to involve or trick any user; the exploit path is entirely attacker-driven.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other variable environmental factors.

Blast Radius

  • Reads all data accessible to JD Edwards EnterpriseOne Tools, including stored business records, configurations, and potentially session or credential material.
  • Inserts, updates, or deletes a subset of JD Edwards EnterpriseOne Tools data, allowing an attacker to tamper with business records or corrupt application state.
  • The scope change (S:C) means impact can propagate beyond the directly compromised component to other products or services that trust or consume JD Edwards EnterpriseOne Tools data.
  • Availability is not directly impacted, but data integrity and confidentiality losses at this scale can cause effective service disruption through corrupted or stolen business-critical records.

How HarborGuard Handles This

Available on HarborGuard: this CVE is ingested and matched against customer images continuously, flagging any image that includes JD Edwards EnterpriseOne Tools at versions 9.2.0.0 through 9.2.26.2. Because Oracle has not published a fix version, no patched-image rebuild can be generated yet; HarborGuard polls the advisory on every ingest cycle and will trigger the rebuild-and-PR flow automatically for customers with auto-remediation enabled the moment an upstream patch is available. While waiting for the upstream fix, recommended compensating controls include applying network-policy rules to restrict HTTP access to JD Edwards EnterpriseOne Tools endpoints to trusted source CIDRs only, enabling egress filtering to limit lateral movement if a container is compromised, and using HarborGuard's policy gates to block promotion of affected images to production registries until a patched version is available.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / JD Edwards EnterpriseOne Tools
    ≤ 9.2.26.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
References