Junglewise Threat Intelligence

CVE-2026-46969: Oracle Financials for EMEA improper access control in Internal Operations

CVE-2026-46969 · Severity: high · CVSS 7.2 · Published 2026-06-17

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Financials for EMEA, a suite of financial management tools used by businesses in Europe, the Middle East, and Africa. A high-privileged attacker could exploit this flaw to gain full control over the application. This could lead to the unauthorized access, modification, or deletion of sensitive financial data and a total disruption of business operations.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Internal Operations component of Oracle Financials for EMEA. It is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the affected component, impacting confidentiality, integrity, and availability. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for June 2026 for remediation steps.

Affected products

  • Oracle Corporation Financials for EMEA (Oracle E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References