Description
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools, permitting an unauthenticated attacker with network access over HTTP to exploit a vulnerability that grants full control over the toolset environment. Exploitation can lead to the compromise of confidentiality, integrity, and availability, effectively allowing the attacker to take over the JD Edwards tools and potentially access or manipulate underlying business data. The CVSS vector clarifies that the component is considered universal, with no requirement for user interaction, making the impact severe and the attack surface wide.

Affected Systems

Oracle Corporation’s JD Edwards EnterpriseOne Tools, especially versions 9.2.0.0 through 9.2.26.2, are affected. Any deployment of these releases that remains exposed to external HTTP traffic is susceptible to the described exploit. No other product variants or subcomponents are listed as affected in the advisory.

Risk and Exploitability

The CVSS score of 9.8 underlines a critical level of risk, and the EPSS estimate of less than 1% indicates a low yet non‑zero likelihood of exploitation in the wild. The vulnerability is not part of CISA’s KEV catalog, suggesting that it has not yet been observed in known supply‑chain attacks. Attackers can trigger the flaw remotely and without authentication by sending crafted HTTP requests to the JD Edwards Toolset, implying that the likelihood of exploitation depends largely on exposure of the service to the network rather than on privilege or user interaction.

Generated by OpenCVE AI on June 17, 2026 at 19:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Immediately upgrade JD Edwards EnterpriseOne Tools to a version beyond 9.2.26.2 or apply the vendor‑specified patch as outlined in Oracle’s security advisory.
  • Restrict network access to the JD Edwards Toolset by implementing firewall rules or VPN, ensuring that only authorized internal users can reach the HTTP interface.
  • Monitor incoming HTTP traffic on the JD Edwards Toolset for anomalous patterns and review logs for signs of exploitation attempts.

Generated by OpenCVE AI on June 17, 2026 at 19:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle jd Edwards Enterpriseone Tools
CPEs cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle jd Edwards Enterpriseone Tools
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Jd Edwards Enterpriseone Tools
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:43:32.677Z

Reserved: 2026-05-18T15:55:10.311Z

Link: CVE-2026-46909

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T00:30:15Z

Weaknesses

No weakness.