Junglewise Threat Intelligence

CVE-2026-46951: Oracle Quality improper privilege management in Internal Operations

CVE-2026-46951 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Quality. Vendors: Oracle.

Executive brief

Oracle Quality, a component of the Oracle E-Business Suite used for managing enterprise quality control and compliance, contains a security vulnerability in its Internal Operations component. A user with low-level access to the system can exploit this flaw over the network to gain full control of the application. This could lead to the unauthorized modification of quality standards, theft of sensitive operational data, or a complete shutdown of quality management processes.

Technical details

This vulnerability exists in the Internal Operations component of Oracle Quality within the Oracle E-Business Suite. It is classified under improper privilege management and authentication bypass (CWE-269, CWE-287, CWE-306). An attacker with low-privileged credentials can exploit this flaw over HTTP without any user interaction. A successful exploit results in a complete takeover of the Oracle Quality product, impacting the confidentiality, integrity, and availability of the system. Affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Quality 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats