Junglewise Threat Intelligence

CVE-2026-46931: Oracle Enterprise Asset Management improper access control in Internal Operations

CVE-2026-46931 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Enterprise Asset Management. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Enterprise Asset Management, a tool used by organizations to manage physical assets and maintenance operations. A user with low-level access to the system can exploit this flaw over the network to gain full control of the application. This could lead to the unauthorized modification of maintenance records, exposure of sensitive operational data, or a complete shutdown of the asset management service.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Internal Operations component of Oracle Enterprise Asset Management. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw does not require user interaction and has a high impact on confidentiality, integrity, and availability, potentially leading to a complete takeover of the affected product. Affected versions include Oracle E-Business Suite 12.2.6 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Enterprise Asset Management 12.2.6-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats