CVE-2026-46883: Critical severity Oracle JD Edwards EnterpriseOne Tools vulnerability
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict JDENET network access to trusted IPs/networks using firewall rules or network ACLs; isolate JD Edwards EnterpriseOne Tools instances from untrusted networks (segment the network) to prevent direct JDENET access from the public internet or untrusted networks.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46883?
The severity of CVE-2026-46883 is rated as critical with a score of 9.8.
How does CVE-2026-46883 affect Oracle JD Edwards EnterpriseOne Tools?
CVE-2026-46883 affects versions 9.2.0.0 through 9.2.26.2 of Oracle JD Edwards EnterpriseOne Tools, allowing unauthorized access to compromise systems.
Can CVE-2026-46883 be exploited remotely?
Yes, CVE-2026-46883 can be exploited by an unauthenticated attacker with network access via JDENET.
What impact does CVE-2026-46883 have on data confidentiality?
CVE-2026-46883 allows for high confidentiality impact, potentially exposing sensitive data.
How can I remediate CVE-2026-46883?
To remediate CVE-2026-46883, users should upgrade to a version of Oracle JD Edwards EnterpriseOne Tools that is not affected by this vulnerability.