Junglewise Threat Intelligence

CVE-2026-46957: Oracle iSupplier Portal improper access control in Internal Operations

CVE-2026-46957 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle iSupplier Portal. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle iSupplier Portal, a platform used by businesses to manage interactions and transactions with their global suppliers. A low-privileged attacker could exploit this flaw to take full control of the portal, potentially leading to the exposure of sensitive procurement data, disruption of supply chain operations, and unauthorized modification of supplier information. While the attack is difficult to execute, a successful breach would compromise the confidentiality and integrity of the entire system.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Internal Operations component of Oracle iSupplier Portal. It is reachable over the network via HTTP and requires the attacker to have low-level authenticated privileges. Although the attack complexity is rated as high, suggesting specific timing or environmental conditions are required, a successful exploit allows for a complete takeover of the portal. This results in high impacts on confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle iSupplier Portal 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats