Junglewise Threat Intelligence

CVE-2026-46821: Oracle E-Business Suite information disclosure in Financials Common Modules

CVE-2026-46821 · Severity: high · CVSS 7.7 · Published 2026-05-28

Technologies: Oracle E-Business Suite Financials Common Modules. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle E-Business Suite Financials Common Modules, which are used by organizations to manage core financial operations and data. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive financial information. This could lead to a significant breach of confidential corporate data and potentially impact other integrated business systems.

Technical details

This vulnerability affects the Common Components of Oracle Financials Common Modules within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an information disclosure flaw that is easily exploitable via HTTP. A low-privileged attacker with network access can bypass intended confidentiality restrictions to access all data within the module. Notably, the vulnerability includes a 'scope change' (S:C), meaning a successful exploit can impact security components beyond the immediate Financials module. Users are advised to refer to the Oracle May 2026 Security Alert for patching information.

Affected products

  • Oracle E-Business Suite Financials Common Modules 12.2.3-12.2.15

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References

Related threats