Junglewise Threat Intelligence

CVE-2026-46938: Oracle Cost Management improper access control in Cost Planning

CVE-2026-46938 · Severity: high · CVSS 7.2 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A vulnerability exists in the Cost Planning component of Oracle Cost Management, a tool used by businesses to track and analyze manufacturing and inventory costs. A high-privileged attacker could exploit this flaw to gain full control over the Cost Management system. This could lead to the unauthorized disclosure of sensitive financial data, modification of cost records, or disruption of accounting operations.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Cost Planning component of Oracle Cost Management. It is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle Cost Management product, impacting the confidentiality, integrity, and availability of the system. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Cost Management 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References