Junglewise Threat Intelligence

CVE-2026-46928: Oracle Spares Management privilege escalation in Internal Operations

CVE-2026-46928 · Severity: high · CVSS 8.8 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Spares Management, a component of the Oracle E-Business Suite used for managing service parts and inventory. A low-privileged user can exploit this flaw over the network to gain full control of the Spares Management system. This could lead to the unauthorized access, modification, or deletion of critical inventory and supply chain data.

Technical details

This vulnerability is located in the Internal Operations component of Oracle Spares Management (Oracle E-Business Suite). It is classified under improper privilege management and authentication bypass (CWE-269, CWE-287, CWE-306). An attacker with low-level authenticated access can exploit the flaw over HTTPS without any user interaction. Successful exploitation results in a complete compromise of the Spares Management component, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Spares Management 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References