CVE-2026-46913: Critical severity Oracle JD Edwards EnterpriseOne Tools vulnerability
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict and isolate access to the infrastructure hosting JD Edwards EnterpriseOne Tools. Apply network ACLs/firewall rules to limit administrative/management access to trusted IPs and trusted networks, place JD Edwards servers in isolated network segments, and block untrusted network access to management interfaces.
- Operational
Audit and monitor logons and administrative activity on systems hosting JD Edwards EnterpriseOne Tools; review and remove or disable unnecessary accounts, enforce least-privilege for accounts with access to the infrastructure, and rotate credentials for privileged accounts.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46913?
CVE-2026-46913 has a severity score of 9.3, indicating it is critical.
How do I fix CVE-2026-46913?
To fix CVE-2026-46913, ensure that you upgrade your JD Edwards EnterpriseOne Tools to a version beyond 9.2.26.2.
Who can exploit CVE-2026-46913?
CVE-2026-46913 can be exploited by an unauthenticated attacker with access to the infrastructure where JD Edwards EnterpriseOne is hosted.
Which versions of Oracle JD Edwards EnterpriseOne Tools are affected by CVE-2026-46913?
The affected versions of Oracle JD Edwards EnterpriseOne Tools are from 9.2.0.0 to 9.2.26.2.
What are the potential impacts of exploiting CVE-2026-46913?
Exploiting CVE-2026-46913 can lead to complete compromise of the system with potential threats to confidentiality, integrity, and availability.