Junglewise Threat Intelligence

CVE-2026-46817: Oracle E-Business Suite remote compromise in Oracle Payments

CVE-2026-46817 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2026-05-28

Technologies: Oracle Payments, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite, a critical enterprise resource planning platform, contains a severe vulnerability in its Oracle Payments module. This module handles sensitive financial transactions and electronic fund transfers. An attacker can exploit this flaw over the internet to gain full control of the payment system, potentially leading to unauthorized financial transactions, data theft, or complete disruption of payment operations.

Technical details

This vulnerability is classified as Improper Privilege Management (CWE-269) and Missing Authentication for Critical Function (CWE-306) within the File Transmission component of Oracle Payments. The flaw is easily exploitable via HTTP without requiring any user interaction or prior authentication. A successful exploit allows a remote attacker to achieve full compromise of the Oracle Payments product, impacting confidentiality, integrity, and availability. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Oracle has addressed this issue in their May 2026 security alert.

Affected products

  • Oracle E-Business Suite (Oracle Payments) 12.2.3 - 12.2.15

Timeline

  • 2026-05-28: disclosed: Initial disclosure by Oracle
  • 2026-05-28: advisory: NVD publication date
  • 2026-06-17: other: Last modified date in NVD record

Related threats