Junglewise Threat Intelligence

CVE-2026-46899: Oracle Enterprise Command Center Framework improper access control in Core

CVE-2026-46899 · Severity: critical · CVSS 9.6 · Published 2026-06-17

Technologies: Oracle Enterprise Command Center Framework. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Oracle Enterprise Command Center Framework, a component of the Oracle E-Business Suite used for data visualization and business intelligence. A low-privileged user can exploit this flaw over the network to gain full access to sensitive business data or modify critical information. This could lead to significant data breaches or unauthorized changes to business records across multiple integrated Oracle products.

Technical details

This vulnerability is classified as improper privilege management (CWE-269) or improper access control (CWE-284) within the Core component of the Oracle Enterprise Command Center Framework. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw is particularly severe because it involves a 'scope change' (CVSS S:C), meaning a successful exploit can impact other products beyond the Command Center itself. Attackers can achieve unauthorized creation, deletion, or modification of all accessible data, as well as complete confidentiality loss of critical data. Users are advised to refer to the Oracle June 2026 security alert for patching information.

Affected products

  • Oracle Enterprise Command Center Framework V15, V16

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats