Junglewise Threat Intelligence

CVE-2026-46934: Oracle E-Business Suite improper access control in Internal Operations

CVE-2026-46934 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle Complex Maintenance, Repair and Overhaul. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle E-Business Suite component used for managing complex maintenance and repair operations. A low-privileged user could exploit this flaw to gain full control over the system, potentially leading to the theft of sensitive data or disruption of maintenance operations. While the attack is difficult to execute, a successful breach would compromise the confidentiality, integrity, and availability of the entire module.

Technical details

This vulnerability is classified under Improper Access Control and Missing Authentication for Critical Function (CWE-284, CWE-306) within the Internal Operations component of Oracle Complex Maintenance, Repair and Overhaul. It is accessible via the network over HTTP and requires low-privileged authentication to exploit. Although the attack complexity is rated as high, a successful exploit allows for a complete takeover of the affected product, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Complex Maintenance, Repair and Overhaul 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD entry published

References

Related threats