CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46907

Critical · CVSS 9.9

JD Edwards EnterpriseOne Order Promising — Improper Access Control (CWE-284) leading to full system takeover

CVSS
9.9
nvd
EPSS
KEV
No
Class
other
CWE-284

Description

Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Oracle JD Edwards (component: Order Promising Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Order Promising. While the vulnerability is in JD Edwards EnterpriseOne Order Promising, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Order Promising. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols Order Promising IntegrationJD Edwards EnterpriseOneEnterpriseOne Order Promising9.2
Keywords CVE-2026-46907JD Edwards EnterpriseOne Order PromisingOrder Promising IntegrationJDE EnterpriseOne 9.2Oracle JD Edwards exploitCWE-284 JD EdwardsOracle JDE RCEJDE Order Promising takeoverCVSS 9.9 JD Edwards
Versions: 9.2

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z