Junglewise Threat Intelligence

CVE-2026-46945: Oracle iSupport takeover in Oracle E-Business Suite Internal Operations

CVE-2026-46945 · Severity: critical · CVSS 9.1 · Published 2026-06-17

Technologies: Oracle Isupport. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle iSupport, a customer service and support module within the Oracle E-Business Suite. A high-privileged attacker can exploit this flaw over the network to gain full control of the iSupport system. Because of the integrated nature of the suite, a successful attack could also allow the intruder to compromise other connected business applications and data.

Technical details

This vulnerability affects the Internal Operations component of Oracle iSupport within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires high administrative privileges (PR:H) but no user interaction. The attack vector is network-based via HTTP. A successful exploit results in a 'scope change' (S:C), meaning the attacker can move beyond the iSupport component to impact other parts of the E-Business Suite environment, leading to a total loss of confidentiality, integrity, and availability. Oracle has addressed this in their June 2026 security update.

Affected products

  • Oracle iSupport (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats