CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46908

Critical · CVSS 9.9

JD Edwards EnterpriseOne Accounts Payable — Improper Access Control (CWE-284) leading to full product takeover

CVSS
9.9
nvd
EPSS
KEV
No
Class
other
CWE-284

Description

Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable. While the vulnerability is in JD Edwards EnterpriseOne Accounts Payable, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Accounts Payable. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols EnterpriseOneAccountsPayableJDEE1AP9.2HTTPscope change
Keywords CVE-2026-46908JD Edwards EnterpriseOneAccounts PayableOracle JDEEnterpriseOne 9.2CWE-284improper access controlJDE AP takeoverOracle Critical Patch Update June 2026
Versions: 9.2

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z