Junglewise Threat Intelligence

CVE-2026-46900: Oracle Enterprise Command Center Framework privilege escalation in Core

CVE-2026-46900 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle Enterprise Command Center Framework. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Oracle Enterprise Command Center Framework, a component of the Oracle E-Business Suite used for data visualization and business intelligence. A user with low-level access to the system can exploit this flaw over the network to take full control of the application. This could lead to the theft of sensitive business data, unauthorized modification of records, or a complete shutdown of the service, potentially impacting other integrated business systems.

Technical details

This vulnerability is classified as Improper Access Control (CWE-284) and Improper Privilege Management (CWE-269) within the Core component of the Oracle Enterprise Command Center Framework. It is easily exploitable by a low-privileged attacker with network access via HTTPS. The flaw is particularly severe because it involves a 'scope change' (CVSS Scope: Changed), meaning a successful exploit can impact components or products beyond the immediate security scope of the framework itself. Successful exploitation allows for a complete takeover of the affected environment, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle June 2026 security alert for patching information.

Affected products

  • Oracle Enterprise Command Center Framework V15, V16

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats