Junglewise Threat Intelligence

CVE-2026-46962: Oracle Project Portfolio Analysis improper privilege management in Internal Operations

CVE-2026-46962 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Project Portfolio Analysis. Vendors: Oracle.

Executive brief

Oracle Project Portfolio Analysis, a component of the Oracle E-Business Suite used by organizations to manage and analyze investment portfolios, contains a security vulnerability. A user with low-level access to the system can exploit this flaw over the network to gain full control of the application. This could lead to the unauthorized viewing of sensitive financial data, modification of project records, or a complete disruption of the portfolio management service.

Technical details

This vulnerability exists in the Internal Operations component of Oracle Project Portfolio Analysis (Oracle E-Business Suite). It is classified under improper privilege management and missing authentication for critical functions (CWE-269, CWE-306). An attacker with low-privileged credentials can exploit this flaw via HTTP without any user interaction. Successful exploitation allows for a complete takeover of the affected component, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle Project Portfolio Analysis 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats