Junglewise Threat Intelligence

CVE-2026-46929: Oracle Cost Management improper access control in Cost Planning

CVE-2026-46929 · Severity: high · CVSS 8.8 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A vulnerability exists in the Cost Planning component of Oracle Cost Management, a tool used by businesses to track and analyze manufacturing and distribution costs. A person with basic user access to the system could exploit this flaw over the network to take full control of the application. This could lead to the unauthorized viewing or modification of sensitive financial data and disruption of cost accounting operations.

Technical details

A vulnerability in the Cost Planning component of Oracle Cost Management (part of Oracle E-Business Suite) allows for improper access control and privilege management. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation can result in a complete takeover of the Oracle Cost Management instance, impacting confidentiality, integrity, and availability. Affected versions include 12.2.3 through 12.2.15. Oracle has addressed this in the June 2026 security alerts.

Affected products

  • Oracle Cost Management 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References