Junglewise Threat Intelligence

CVE-2026-46946: Oracle iSupport takeover in Internal Operations component

CVE-2026-46946 · Severity: critical · CVSS 9.1 · Published 2026-06-17

Technologies: Oracle Isupport. Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle iSupport, a customer service and support module within the Oracle E-Business Suite. A high-privileged attacker can exploit this flaw to take full control of the iSupport system, potentially leading to the theft of sensitive customer data or disruption of support operations. Because of the integrated nature of the E-Business Suite, an attack on this component could also impact other connected business systems and data.

Technical details

This vulnerability affects the Internal Operations component of Oracle iSupport within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an 'easily exploitable' flaw that allows a high-privileged attacker with network access via HTTP to compromise the application. The vulnerability is notable for a 'scope change' (S:C), meaning a successful exploit can impact components beyond the immediate security scope of Oracle iSupport. Successful exploitation can result in a complete takeover of the affected product, impacting confidentiality, integrity, and availability. While specific CWE details are not provided by the vendor, the impact suggests a significant authorization or injection-related failure.

Affected products

  • Oracle iSupport 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats