Junglewise Threat Intelligence

CVE-2026-46939: Oracle E-Business Suite improper access control in Configure to Order

CVE-2026-46939 · Severity: high · CVSS 8.1 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A vulnerability exists in the Supply to Order Workbench component of Oracle E-Business Suite. This flaw allows an authorized user with low-level permissions to gain unauthorized access to sensitive business data. An attacker could potentially view, modify, or delete critical configuration and supply chain information, leading to significant data integrity issues and operational disruption.

Technical details

An improper access control vulnerability (CWE-284) exists in the Supply to Order Workbench component of Oracle Configure to Order (part of Oracle E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended restrictions to create, modify, or delete critical data, or gain full read access to all data accessible by the Configure to Order product. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle June 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle Configure to Order 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle published vendor advisory

References

Related threats