CVE-2026-46878: Critical severity Oracle JD Edwards EnterpriseOne Tools vulnerability
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to JDENET for JD Edwards EnterpriseOne Tools: block or allow only trusted IP addresses and networks using firewalls/ACLs, network segmentation, or WAFs; isolate JD Edwards EnterpriseOne Tools instances from untrusted networks to prevent unauthenticated network access via JDENET.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46878?
CVE-2026-46878 has a critical severity score of 9.8.
How do I fix CVE-2026-46878?
To fix CVE-2026-46878, update your Oracle JD Edwards EnterpriseOne Tools to version 9.2.27 or higher.
Who is affected by CVE-2026-46878?
All users of Oracle JD Edwards EnterpriseOne Tools versions 9.2.0.0 to 9.2.26.2 are affected by CVE-2026-46878.
What type of vulnerability is CVE-2026-46878?
CVE-2026-46878 is an easily exploitable vulnerability that allows unauthenticated attackers remote network access.
What components of Oracle JD Edwards does CVE-2026-46878 impact?
CVE-2026-46878 impacts the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools.