CVE-2026-46903: High severity Oracle JD Edwards EnterpriseOne Tools vulnerability
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable HTTP access to JD Edwards EnterpriseOne Tools if it is not required. If HTTP access is required, restrict it to trusted management networks or a VPN and enforce strict access controls.
Oracle JD Edwards EnterpriseOne Tools HTTP network access = disabled or restricted to trusted IPs/VPN - Compensating control
Restrict access to JD Edwards EnterpriseOne Tools HTTP interfaces at the network perimeter using firewalls or ACLs; place the service behind a VPN, reverse proxy, or WAF to limit exposure to untrusted networks.
- Operational
Monitor logs and audit for signs of compromise. If compromise is suspected or after remediation, rotate administrative and service credentials and review user accounts and privileges.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46903?
CVE-2026-46903 has a severity rating of 8.8, classified as high.
How do I fix CVE-2026-46903?
To fix CVE-2026-46903, upgrade your Oracle JD Edwards EnterpriseOne Tools to version 9.2.26.3 or higher.
What are the affected versions of CVE-2026-46903?
The affected versions for CVE-2026-46903 are 9.2.0.0 to 9.2.26.2 of Oracle JD Edwards EnterpriseOne Tools.
What type of vulnerability is CVE-2026-46903?
CVE-2026-46903 is an easily exploitable vulnerability that allows low privileged attackers with network access to compromise the system.
What component is affected in CVE-2026-46903?
CVE-2026-46903 affects the Business Logic Infrastructure Security component of the JD Edwards EnterpriseOne Tools.