Junglewise Threat Intelligence

CVE-2026-46923: Oracle Public Sector Financials Authorization compromise in E-Business Suite

CVE-2026-46923 · Severity: high · CVSS 8 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Authorization component of Oracle Public Sector Financials, a suite used by government entities to manage international financial operations. A highly privileged attacker could exploit this flaw to take full control of the system, potentially leading to the theft of sensitive financial data or disruption of government accounting services. While the attack is difficult to execute, a successful breach could also impact other connected business systems.

Technical details

This vulnerability is located in the Authorization component of Oracle Public Sector Financials (International) within the Oracle E-Business Suite. It is classified as a high-severity issue (CVSS 8.0) that allows a high-privileged attacker with network access via HTTP to compromise the system. The exploit is considered difficult to perform (High Attack Complexity) but results in a Scope change, meaning a successful attack can impact components beyond the immediate application. Successful exploitation can lead to a complete takeover of the affected product, impacting confidentiality, integrity, and availability. Affected versions include 12.2.3 through 12.2.15.

Affected products

  • Oracle Corporation Public Sector Financials (International) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats