Junglewise Threat Intelligence

CVE-2026-46837: Oracle Flow Manufacturing security bypass in E-Business Suite

CVE-2026-46837 · Severity: high · CVSS 8.8 · Published 2026-05-28

Technologies: Oracle Flow Manufacturing. Vendors: Oracle.

Executive brief

A security vulnerability exists in Oracle Flow Manufacturing, a component of the Oracle E-Business Suite used for production scheduling and manufacturing management. An attacker with basic user access can exploit this flaw over the network to gain full control over the manufacturing system. This could lead to the theft of sensitive production data, disruption of manufacturing operations, or unauthorized changes to business records.

Technical details

This vulnerability affects the Security component of Oracle Flow Manufacturing within Oracle E-Business Suite versions 12.2.9 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via SQL. While the specific CWE is not detailed in the advisory, the attack vector and impact suggest a breakdown in access controls or input validation that allows for a complete takeover of the affected component. Successful exploitation results in high impacts to confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Flow Manufacturing 12.2.9-12.2.15

Timeline

  • 2026-05-28: disclosed: Initial disclosure by Oracle and NVD publication.

References

Related threats