Junglewise Threat Intelligence

CVE-2026-46897: Oracle Enterprise Command Center Framework improper access control in Core

CVE-2026-46897 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle Enterprise Command Center Framework. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Oracle Enterprise Command Center Framework, a component of the Oracle E-Business Suite used for data visualization and business intelligence. An attacker with basic user credentials can gain unauthorized access to view, modify, or delete sensitive business data across the system. This could lead to a total compromise of the application's data integrity and availability, potentially impacting other connected business systems.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Core component of the Oracle Enterprise Command Center Framework. It is easily exploitable via HTTP by a low-privileged attacker with network access. The flaw involves a 'scope change' (Status: Changed in CVSS), meaning a successful exploit allows the attacker to impact components beyond the immediate framework. Impact includes unauthorized creation, deletion, or modification of all accessible data, as well as the ability to cause a partial denial of service. The vulnerability affects versions V15 and V16 of the framework.

Affected products

  • Oracle Enterprise Command Center Framework V15, V16

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats