Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-46911

CVE-2026-46911: JD Edwards Project Costing Auth Bypass

CVE-2026-46911 is an authentication bypass vulnerability in Oracle JD Edwards EnterpriseOne Project Costing that enables unauthorized data access and modification. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-46911 Overview

CVE-2026-46911 is an improper access control vulnerability [CWE-284] in the Oracle JD Edwards EnterpriseOne Project Costing product. The flaw resides in the Job Costing component and affects version 9.2. A low-privileged attacker with network access via the JDENET protocol can exploit this issue with low attack complexity and no user interaction.

Successful exploitation allows unauthorized creation, deletion, or modification of critical data and complete read access to all data accessible by Project Costing. The vulnerability includes a scope change, meaning attacks may significantly impact additional Oracle products beyond Project Costing itself.

Critical Impact

Authenticated network attackers can achieve full read and write access to Project Costing data with cross-component impact through the JDENET communication channel.

Affected Products

  • Oracle JD Edwards EnterpriseOne Project Costing 9.2
  • Oracle JD Edwards EnterpriseOne Job Costing component
  • Additional Oracle JD Edwards EnterpriseOne products reachable via scope change

Discovery Timeline

Technical Details for CVE-2026-46911

Vulnerability Analysis

The vulnerability stems from improper access control [CWE-284] within the Job Costing component of JD Edwards EnterpriseOne Project Costing. Authorization checks fail to adequately restrict operations issued through the JDENET protocol, the proprietary communication channel used by EnterpriseOne kernel processes and clients.

An authenticated attacker holding low-tier application privileges can issue JDENET requests that bypass intended permission boundaries. The resulting access enables unauthorized read, create, modify, and delete operations against all Project Costing data.

The scope change indicates that the vulnerable component grants access beyond its own security authority. Exploitation can therefore affect data managed by adjacent EnterpriseOne products that share trust relationships with Project Costing.

Root Cause

The root cause is missing or insufficient authorization enforcement on JDENET service handlers within the Job Costing component. The component trusts the caller's session context without verifying that the requested operation matches the user's assigned roles and data permissions.

Attack Vector

Exploitation requires network reachability to the JDENET listener and a valid low-privileged EnterpriseOne account. The attacker sends crafted JDENET messages targeting Job Costing service endpoints to invoke privileged data operations. No user interaction is required, and the attack complexity is low. Public proof-of-concept code is not available, and the EPSS probability remains low at the time of publication. Technical details are described in the Oracle Security Alert cspujun2026.

Detection Methods for CVE-2026-46911

Indicators of Compromise

  • Unexpected JDENET connections to EnterpriseOne kernel processes from non-application-tier hosts
  • Unusual Project Costing or Job Costing record creation, modification, or deletion by low-privilege accounts
  • Audit log entries showing data access patterns inconsistent with the account's assigned role
  • Spikes in JDENET message volume targeting Job Costing service endpoints

Detection Strategies

  • Enable and centralize EnterpriseOne security and audit logging, then alert on cross-product data access originating from Project Costing sessions
  • Baseline normal JDENET traffic per user and flag deviations in operation type or record volume
  • Correlate database write operations on F51* (Job Cost) tables with the originating EnterpriseOne user session

Monitoring Recommendations

  • Forward JD Edwards server logs, JDENET trace logs, and database audit trails to a centralized analytics platform for retention and correlation
  • Monitor authentication events for low-privileged accounts performing administrative-style data operations
  • Track outbound network connections from the Project Costing tier to adjacent EnterpriseOne services for lateral activity

How to Mitigate CVE-2026-46911

Immediate Actions Required

  • Apply the patches from the Oracle Security Alert cspujun2026 to all JD Edwards EnterpriseOne 9.2 environments
  • Inventory all hosts running Project Costing and the Job Costing component to confirm patch coverage
  • Review and reduce Project Costing role assignments, removing unnecessary low-privilege accounts with JDENET access
  • Rotate credentials for any account suspected of exposure prior to patching

Patch Information

Oracle addressed CVE-2026-46911 in the June 2026 Critical Patch Update for JD Edwards. Customers on version 9.2 must install the corresponding Tools Release and ESU updates referenced in the Oracle advisory. No vendor-approved workaround replaces patching.

Workarounds

  • Restrict network access to the JDENET listener ports using firewall rules so that only trusted application-tier hosts can connect
  • Enforce least privilege by auditing Project Costing security records and removing data access beyond business need
  • Place EnterpriseOne servers behind a segmented management network with jump-host access only
  • Increase audit log retention and review frequency until patches are deployed across all environments

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.