Junglewise Threat Intelligence

CVE-2026-46930: Oracle E-Business Suite improper access control in In-Memory Cost Management

CVE-2026-46930 · Severity: critical · CVSS 9.1 · Published 2026-06-17

Vendors: Oracle Corporation, Oracle.

Executive brief

A critical vulnerability exists in Oracle E-Business Suite's cost management software, which is used by manufacturing companies to manage financial data and operational costs. An unauthenticated attacker can remotely access the system over the network to view, modify, or delete sensitive business data. This could lead to significant financial data inaccuracy, loss of proprietary cost structures, and unauthorized changes to critical business records.

Technical details

An improper access control vulnerability (CWE-284) exists in the Internal Operations component of Oracle In-Memory Cost Management for Discrete Industries within Oracle E-Business Suite. The flaw is easily exploitable by an unauthenticated attacker with network access via HTTPS. A successful exploit allows the attacker to gain unauthorized access to all data within the component, including the ability to create, delete, or modify critical records. Affected versions include 12.2.12 through 12.2.15. The vulnerability has a CVSS 3.1 base score of 9.1, reflecting high impacts on confidentiality and integrity without affecting availability.

Affected products

  • Oracle Corporation In-Memory Cost Management for Discrete Industries 12.2.12-12.2.15

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats