Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-46817

Published 2026-05-28
Updated 2 months ago
Vendor/s
Oracle
Product/s
E-Business Suite
Version/s
12.2.3 > 12.2.15
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
9.8
/ 10
Critical
Severity Details
Base score
9.8 Critical
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-46817 is a critical 9.8 CVSS vulnerability in Oracle E-Business Suite (12.2.3-12.2.15) allowing unauthenticated takeover of Oracle Payments.

CPE

Oracle logo
Oracle
Product Version Start Version End (excl.) Status
e-business_suite 12.2.3 12.2.15 vulnerable

Related weakness (CWE)

CWE-269, CWE-287, CWE-306

Remediation plan

1

Apply official patches

Immediately apply the security updates provided by Oracle in the May 2026 Critical Patch Update (CPU) specifically targeting the Oracle Payments component of E-Business Suite.

2

Update affected systems

Ensure all Oracle E-Business Suite instances currently running versions 12.2.3 through 12.2.15 are upgraded to the latest patched release to mitigate unauthenticated network exploitation.

3

Restrict access

Isolate the Oracle Payments File Transmission component from the public internet. Implement strict IP whitelisting for HTTP traffic and ensure the system is protected by a Web Application Firewall (WAF) and VPN.

4

Monitor for exploitation

Conduct a forensics triage as per CISA BOD 26-04 guidance. Audit Oracle Payments for unauthorized administrative changes, new user accounts, or suspicious file transmission activity in system logs.

Detection Guidance

Monitor HTTP server logs for unusual or unauthenticated requests directed at the Oracle Payments File Transmission endpoints. Look for suspicious POST requests originating from external or unknown IP addresses. Security teams should deploy WAF signatures designed to detect unauthorized access to Oracle E-Business Suite financial modules and review system audit trails for signs of privilege escalation or unauthorized configuration modifications consistent with the CWE-269 and CWE-306 identifiers.

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management