CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46905

Critical · CVSS 9.8

JD Edwards EnterpriseOne Tools — Missing Authentication for Critical Function (CWE-306) leading to unauthenticated RCE / full takeover via HTTP

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-306

Description

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols Web Runtime SecurityJDEBaseEnterpriseOnejde.iniJDENetWebRuntimeorchestratorAIS ServerE1OrchestratorService
Keywords CVE-2026-46905JD Edwards EnterpriseOne ToolsWeb Runtime Securityunauthenticatedauthentication bypassCWE-306Oracle JD Edwards PoCJDE EnterpriseOne RCE9.2.26.2Oracle Critical Patch Update June 2026
Versions: 9.2.0.0 - 9.2.26.2

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z