Junglewise Threat Intelligence

CVE-2026-46822: Oracle iAssets takeover via Internal Operations component

CVE-2026-46822 · Severity: critical · CVSS 9.9 · Published 2026-05-28

Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle iAssets, a component of the Oracle E-Business Suite used for managing corporate assets. An attacker with basic user access can remotely take full control of the system over the network. This could lead to the theft of sensitive financial data, disruption of business operations, and potential unauthorized access to other connected corporate systems.

Technical details

A vulnerability in the Internal Operations component of Oracle iAssets (Oracle E-Business Suite) allows for a complete system takeover. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Notably, the vulnerability involves a 'scope change' (Status: Changed in CVSS), meaning a successful exploit can impact components and data beyond the immediate Oracle iAssets environment. The vulnerability affects versions 12.2.3 through 12.2.15. Attackers can achieve full Confidentiality, Integrity, and Availability impact without any user interaction.

Affected products

  • Oracle iAssets 12.2.3-12.2.15

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References