← Vulnerability feed

Vulnerability record · CVE-2026-46817 · published 28 May 2026

CVE-2026-46817: Oracle E-Business Suite Payments missing authentication allows takeover

Oracle · E Business Suite

Oracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthenticated attacker with network access over HTTP can compromise the component, and successful exploitation results in takeover of Oracle Payments. It is in CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.

9.8 CVSS 3.1 Critical CISA KEV since 15 Jul 2026 EPSS 0.81% · top 44.7% CWE-269 · Improper privilege managementCWE-287 · Improper authentication
9.8CVSS 3.1 base score
0.81%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
21 Jul 2026Last modified by NVD

Description

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated network takeover of a payment component combined with CISA KEV listing and a near-term remediation deadline.

What it is

Oracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 contains an easily exploitable flaw in the File Transmission component. An unauthenticated attacker with network access over HTTP can compromise the component, and successful exploitation results in takeover of Oracle Payments. It is in CISA's Known Exploited Vulnerabilities catalog, so it is being exploited in the wild.

Impact

An attacker gains full compromise of Oracle Payments, with high confidentiality, integrity and availability impact, effectively taking over the component and its payment data and functions.

Attack surface

Reachable over the network via HTTP with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The flaw maps to missing authentication and improper privilege management in the File Transmission component.

Exploitation

Listed in CISA KEV with a remediation due date of 2026-07-18, indicating known exploitation; EPSS 30-day probability is 0.13017 (96th percentile). No ransomware campaign use is documented.

What to do

  • Apply the Oracle CPU May 2026 patches for Oracle E-Business Suite Payments per the vendor advisory.
  • If patching is not immediately possible, restrict or block network access to the affected Oracle Payments File Transmission endpoints, especially from the internet.
  • Follow CISA BOD 26-04 guidance, including evaluating internet exposure and discontinuing use if mitigations are unavailable.
  • Verify no unauthorized changes to Oracle Payments configuration, files and database accounts after exposure.
  • Track the CISA KEV due date of 2026-07-18 and confirm remediation completion.

Detection

  • Review HTTP access logs for unauthenticated requests to Oracle Payments File Transmission endpoints, including anomalous or unexpected paths.
  • Monitor for new or modified privileged accounts, roles and payment configuration changes in Oracle E-Business Suite.
  • Alert on outbound connections or file transfers from the Oracle Payments host that are not part of normal business flows.
  • Correlate E-Business Suite audit logs for File Transmission activity outside normal processing windows.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2026-46817 to the Known Exploited Vulnerabilities catalog on 15 July 2026 as "Oracle E-Business Suite Improper Privilege Management Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 18 July 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-46817 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-21587Oracle E-Business Suite Desktop Integrator unauthenticated file upload RCEOracle Web Applications Desktop Integrator in Oracle E-Business Suite (versions 12.2.3-12.2.11) fails to require authentication for a critical upload…KEVEPSS 98%analysed10.0CVE-2015-4839Oracle e-business suite vulnerabilityUnspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affec…EPSS 3.8%10.0CVE-2015-4798Oracle e-business suite vulnerabilityUnspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affec…EPSS 3.9%10.0CVE-2008-1826Oracle e-business suite vulnerabilityMultiple unspecified vulnerabilities in Oracle E-Business Suite 11.5.10.2 have unknown impact and attack vectors related to (a) Advanced Pricing, aka…EPSS 2.2%10.0CVE-2008-0340Oracle application server vulnerabilityMultiple unspecified vulnerabilities in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 have unknown impact and remote atta…EPSS 2.6%10.0CVE-2008-0343Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and r…EPSS 2.6%10.0CVE-2008-0344Oracle application server vulnerabilityUnspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.3 has unknown impact and remote attack vectors, aka …EPSS 2.6%10.0CVE-2008-0345Oracle application server vulnerabilityUnspecified vulnerability in the Core RDBMS component in Oracle Database 11.1.0.6 has unknown impact and remote attack vectors, aka DB08.EPSS 2.6%

Source: NIST National Vulnerability Database (record CVE-2026-46817), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.