Junglewise Threat Intelligence

CVE-2026-46952: Oracle Quality improper privilege management in Internal Operations

CVE-2026-46952 · Severity: high · CVSS 8.8 · Published 2026-06-17

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in Oracle Quality, a component of the Oracle E-Business Suite used for enterprise quality management and data collection. An attacker with basic user credentials can exploit this flaw over the network to gain full control of the Oracle Quality system. This could lead to the theft of sensitive business data, unauthorized modification of quality records, or a total disruption of quality management operations.

Technical details

This vulnerability is located in the Internal Operations component of Oracle Quality within Oracle E-Business Suite. It is classified under improper privilege management and authentication bypass (CWE-269, CWE-287, CWE-306). An attacker with low-privileged user access can exploit this flaw over the network via HTTP without any user interaction. A successful exploit allows for a complete takeover of the Oracle Quality product, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Quality 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References