Junglewise Threat Intelligence

CVE-2026-46959: Oracle Subledger Accounting improper access control in Internal Operations

CVE-2026-46959 · Severity: high · CVSS 7.5 · Published 2026-06-17

Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Subledger Accounting, a tool used within the Oracle E-Business Suite to manage financial records and accounting entries. A low-privileged user could exploit this flaw to gain full control over the accounting system. This could lead to unauthorized access to sensitive financial data, disruption of accounting operations, or the manipulation of financial records.

Technical details

This vulnerability (CVE-2026-46959) affects the Internal Operations component of Oracle Subledger Accounting within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an improper access control or privilege management issue (CWE-269, CWE-284). An attacker with low-level privileges and network access via HTTP can exploit this flaw, though Oracle notes the attack complexity is high, suggesting specific conditions or timing may be required. A successful exploit results in a complete takeover of the Subledger Accounting product, impacting confidentiality, integrity, and availability. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle Subledger Accounting 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats