CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46906

Critical · CVSS 9.6

JD Edwards EnterpriseOne Tools — Improper Access Control (CWE-284) - Unauthorized data access and modification via HTTP

CVSS
9.6
nvd
EPSS
KEV
No
Class
other
CWE-284

Description

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).

Search profile — drives PoC discovery

Symbols Enterprise Infrastructure SecurityEnterpriseOne ToolsJD EdwardsHTTP network accessscope changeCWE-284
Keywords CVE-2026-46906JD Edwards EnterpriseOne ToolsEnterprise Infrastructure SecurityOracle JD Edwards exploitJD Edwards access control bypassJD Edwards HTTP privilege escalationJD Edwards 9.2 vulnerabilityJD Edwards PoC
Versions: 9.2.0.0 - 9.2.26.2

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z