Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability resides in the Enterprise Infrastructure Security component of JD Edwards EnterpriseOne Tools. It permits an attacker without any authentication to gain full control of the application through the JDENET network interface. Unauthorized intrusion can lead to direct manipulation, deletion, or exfiltration of data and alteration of system configurations, effectively granting the attacker administrative privileges across the platform. The flaw is a classic example of improper authentication (CWE-287), resulting in confidentiality, integrity, and availability compromise.

Affected Systems

The issue affects Oracle JD Edwards EnterpriseOne Tools versions 9.2.0.0 through 9.2.26.2. Systems running any of these releases must be examined to confirm deployment of the tool, as the vulnerability is embedded in the core Enterprise Infrastructure Security component.

Risk and Exploitability

The CVSS 3.1 Base Score of 9.8 denotes critical impact, and the EPSS score of less than 1% indicates a low but non‑zero likelihood of exploitation at the time of publishing. The vulnerability is not listed in CISA’s KEV catalog, yet the lack of authentication combined with network reachability renders it highly attractive to adversaries. Attackers would need only network access to the JDENET port to trigger the flaw; no user interaction or privilege escalation steps are required beyond exploiting the unauthenticated entry point.

Generated by OpenCVE AI on June 17, 2026 at 20:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Oracle security patch or update for JD Edwards EnterpriseOne Tools that addresses this vulnerability (if one exists in the 9.2.x range).
  • Restrict JDENET access to trusted hosts only and/or block the JDENET port (default 5000) from external networks.
  • Disable or uninstall the JDENET component if it is not required for business operations, and ensure the application is not exposed to untrusted networks.

Generated by OpenCVE AI on June 17, 2026 at 20:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T15:38:52.543Z

Reserved: 2026-05-18T15:55:10.309Z

Link: CVE-2026-46883

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T04:00:02Z

Weaknesses

No weakness.