CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46892

Critical · CVSS 9.1

JD Edwards EnterpriseOne Human Resources Management — Improper Access Control / Missing Authentication for Critical Function (CWE-284, CWE-306)

CVSS
9.1
nvd
EPSS
KEV
No
Class
other
CWE-284, CWE-306

Description

Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Human Resources Management accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Human Resources Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

Search profile — drives PoC discovery

Symbols JD Edwards EnterpriseOneHuman Resources ManagementHRME1JDE9.2unauthenticated HTTPCWE-284CWE-306
Keywords CVE-2026-46892JD Edwards EnterpriseOne Human ResourcesJDE HRM unauthenticatedOracle JD Edwards access control bypassJDE EnterpriseOne 9.2 exploitJDE HR missing authenticationOracle JD Edwards CVE-2026-46892 PoC
Versions: 9.2

References

Status: enriched · ingested 2026-06-26T06:00:38.000Z · profiled 2026-07-01T12:30:14.000Z