CVE-2026-46880: Critical severity Oracle JD Edwards EnterpriseOne Tools vulnerability
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to JDENET: block or limit JDENET traffic at perimeter and internal firewalls/ACLs so only trusted management IPs or network segments can reach JD Edwards EnterpriseOne Tools. Ensure JDENET is not directly reachable from untrusted networks (including the Internet).
- Compensating control
Isolate JD Edwards EnterpriseOne Tools instances onto a dedicated management/administration network or VLAN with strict access controls and segmentation from general user and Internet-facing networks.
- Operational
Monitor and log JDENET-related activity and server logs for signs of exploitation; investigate any suspicious access. Track vendor advisories and apply official patches/fixes from Oracle for JD Edwards EnterpriseOne Tools as soon as they are released.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46880?
CVE-2026-46880 has a critical severity rating of 9.8.
How do I fix CVE-2026-46880?
To fix CVE-2026-46880, update Oracle JD Edwards EnterpriseOne Tools to the latest version beyond 9.2.26.2.
Who can exploit CVE-2026-46880?
CVE-2026-46880 can be exploited by an unauthenticated attacker with network access via JDENET.
What components are affected by CVE-2026-46880?
CVE-2026-46880 affects the Enterprise Infrastructure Security component of Oracle JD Edwards EnterpriseOne Tools.
What versions of Oracle JD Edwards are vulnerable to CVE-2026-46880?
The vulnerable versions of Oracle JD Edwards EnterpriseOne Tools are 9.2.0.0 to 9.2.26.2.