Junglewise Threat Intelligence

CVE-2026-46958: Oracle Subledger Accounting privilege escalation in Internal Operations

CVE-2026-46958 · Severity: high · CVSS 7.5 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Subledger Accounting component of the Oracle E-Business Suite, which is used by organizations to manage financial records and accounting data. A low-privileged user could potentially take full control of the accounting system, leading to the unauthorized access, modification, or deletion of sensitive financial information. While the attack is complex to execute, a successful exploit could result in a total compromise of the application's integrity and availability.

Technical details

This vulnerability is located in the Internal Operations component of Oracle Subledger Accounting (part of Oracle E-Business Suite). It is classified under improper privilege management and access control (CWE-269, CWE-284). An attacker with low-level credentials can exploit this flaw over the network via HTTP. Although the attack complexity is high, a successful exploit allows for a complete takeover of the Subledger Accounting product, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Subledger Accounting 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats