• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-46817: pre-auth improper privilege management in Oracle E-Business Suite

Unauthenticated attackers can remotely take over the Oracle Payments component of Oracle E-Business Suite; this is tracked as CVE-2026-46817. The flaw affects Oracle E-Business Suite versions 12.2.3 through 12.2.15 and can be exploited by an attacker with network access via HTTP without any valid account or user interaction. Successful exploitation can lead to full confidentiality, integrity, and availability loss for the Payments component.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.8CRITICAL
EPSS
0.00814
CWE
CWE-269
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: this issue is listed on CISA’s Known Exploited Vulnerabilities catalog with a mandated remediation deadline, and public exploit code exists — treat exposed Oracle Payments instances as high priority for mitigation. Follow the vendor instructions and CISA guidance immediately to reduce internet exposure and apply recommended mitigations.

What is CVE-2026-46817?

Unauthenticated attackers can remotely take over the Oracle Payments component of Oracle E-Business Suite; this is tracked as CVE-2026-46817. The flaw affects Oracle E-Business Suite versions 12.2.3 through 12.2.15 and can be exploited by an attacker with network access via HTTP without any valid account or user interaction. Successful exploitation can lead to full confidentiality, integrity, and availability loss for the Payments component. The weakness is classified as CWE-269 (Improper Privilege Management).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Oracle E-Business Suite are affected?

BRANCHAFFECTEDFIXED
12.x12.2.3 – 12.2.15

Is CVE-2026-46817 being exploited?

CISA added CVE-2026-46817 to the Known Exploited Vulnerabilities catalog on 2026-07-15, and U.S. federal agencies were required to remediate by 2026-07-18. Public exploit code for this vulnerability is available.

How to fix CVE-2026-46817

  1. Isolate or remove internet access to Oracle Payments instances until mitigations are applied.
  2. Apply any vendor-provided mitigations or configuration changes immediately per Oracle guidance and CISA recommendations.
  3. Follow CISA BOD 26-04 prioritization and forensics triage instructions for affected assets.
  4. Increase monitoring and logging for Oracle E-Business Suite, and block or rate-limit HTTP access to the Payments component where feasible.

Frequently asked questions

Is CVE-2026-46817 being actively exploited?

CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog on 2026-07-15 and public exploit code is available.

Which Oracle E-Business Suite versions are affected by CVE-2026-46817?

Oracle E-Business Suite versions 12.2.3 through 12.2.15 are affected by CVE-2026-46817.

Is there a patch for CVE-2026-46817?

There is no fixed version listed; follow Oracle’s mitigations and CISA guidance until a vendor patch is released or a fixed version is published.

Does CVE-2026-46817 require authentication?

No, the vulnerability allows an unauthenticated attacker with network access via HTTP to target the Oracle Payments component.

References