Junglewise Threat Intelligence

CVE-2026-46935: Oracle E-Business Suite privilege escalation in Complex Maintenance Repair and Overhaul

CVE-2026-46935 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle Complex Maintenance, Repair and Overhaul. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle's maintenance and repair software within the E-Business Suite. A user with low-level access to the system could exploit this flaw to take full control of the application. This could lead to unauthorized access to sensitive maintenance data, disruption of repair operations, and a total loss of system integrity.

Technical details

This vulnerability affects the Internal Operations component of Oracle Complex Maintenance, Repair and Overhaul, part of the Oracle E-Business Suite. It is classified under improper access control and privilege management (CWE-284, CWE-269). An attacker with low-privileged credentials can exploit this flaw over the network via HTTP. While the attack is considered difficult to execute (High Attack Complexity), a successful exploit results in a complete takeover of the affected component, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Complex Maintenance, Repair and Overhaul 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats