Junglewise Threat Intelligence

CVE-2026-46961: Oracle Project Portfolio Analysis takeover in Internal Operations

CVE-2026-46961 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Project Portfolio Analysis. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Project Portfolio Analysis, a tool used by organizations to manage and evaluate investment portfolios within the Oracle E-Business Suite. An attacker with basic user access can exploit this flaw to take full control of the application. This could lead to the unauthorized viewing of sensitive financial data, modification of project records, or a complete disruption of portfolio management operations.

Technical details

This vulnerability is located in the Internal Operations component of Oracle Project Portfolio Analysis (Oracle E-Business Suite). It is classified under improper authentication and privilege management (CWE-287, CWE-269, CWE-306). An attacker with low-privileged user credentials can exploit the flaw over the network via HTTP without any user interaction. A successful exploit results in a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability affects versions 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation.

Affected products

  • Oracle Project Portfolio Analysis 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats