CVE-2026-46910
Undergoing Analysis Undergoing Analysis - In Progress
Unauthenticated Remote Code Execution in JD Edwards EnterpriseOne Tools

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
oracle jd_edwards_enterpriseone_tools From 9.2.0.0 (inc) to 9.2.26.2 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards, specifically in the Enterprise Infrastructure Security component. It affects supported versions from 9.2.0.0 to 9.2.26.2.

The vulnerability is easily exploitable by an unauthenticated attacker who has network access via HTTP. Such an attacker can compromise the JD Edwards EnterpriseOne Tools.

Successful exploitation can lead to unauthorized access to critical data or complete access to all data accessible through JD Edwards EnterpriseOne Tools. Additionally, the attacker can cause the system to hang or repeatedly crash, resulting in a complete denial of service (DoS).

The CVSS 3.1 base score is 9.1, indicating a high severity with significant confidentiality and availability impacts.

Impact Analysis

This vulnerability can have serious impacts including unauthorized access to critical or all accessible data within JD Edwards EnterpriseOne Tools.

It can also cause the system to hang or crash repeatedly, resulting in a complete denial of service (DoS), which disrupts availability.

Because the vulnerability can be exploited without authentication and remotely via HTTP, it poses a significant risk to the confidentiality and availability of your data and services.

Compliance Impact

This vulnerability allows an unauthenticated attacker with network access to gain unauthorized access to critical data within JD Edwards EnterpriseOne Tools, potentially compromising confidentiality.

Such unauthorized access to sensitive data can lead to violations of data protection regulations and standards such as GDPR and HIPAA, which require strict controls to protect personal and sensitive information.

Additionally, the vulnerability can cause denial of service, impacting availability, which is also a key requirement in many compliance frameworks.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46910. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart