Unauthenticated File Transmission Vulnerability in Oracle E-Business Suite Payments
CVE-2026-46817
Key Information:
- Vendor
Oracle
- Status
- Vendor
- CVE Published:
- 28 May 2026
Badges
What is CVE-2026-46817?
CVE-2026-46817 is a critical vulnerability found in the Oracle Payments component of the Oracle E-Business Suite. This software suite is utilized by organizations for various business processes, including financial management. The vulnerability allows unauthenticated attackers with network access via HTTP to exploit Oracle Payments, potentially leading to unauthorized control over the application. The severity of this vulnerability is underscored by its high CVSS score of 9.8, which indicates significant risks to confidentiality, integrity, and availability. Organizations utilizing affected versions (12.2.3 to 12.2.15) are at high risk, as successful exploitation could result in severe operational disruptions and compromise sensitive financial data.
Potential impact of CVE-2026-46817
-
Unauthorized Access and Data Compromise: The vulnerability allows attackers to gain unauthorized access to Oracle Payments, potentially leading to the compromise of confidential financial data stored within the application.
-
Operational Disruptions: Successful exploitation can result in the takeover of the Oracle Payments system, which may disrupt payment processing and related financial transactions, significantly impacting business operations.
-
Increased Risk of Ransomware Payloads: The ease of exploitation could attract malicious actors, increasing the likelihood of ransomware attacks, as attackers may seek to leverage the vulnerability for greater network access within an organization.
CISA has reported CVE-2026-46817
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2026-46817 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace as recent news articles suggest the vulnerability is being used by ransomware groups.
The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Affected Version(s)
Oracle Payments 12.2.3 <= 12.2.15
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
CISA orders feds to patch actively exploited Oracle flaw by Saturday
CISA has ordered federal agencies to secure their systems by Saturday against ongoing attacks exploiting a critical vulnerability in the Oracle E-Business Suite financial application.
1 week ago
Week in review: SimpleHelp vulnerability exploited, Oracle EBS Payments flaw under attack - Help Net Security
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Companies keep bolting AI onto their products, and the
3 weeks ago
Over 900 Oracle E-Business instances exposed to ongoing attacks
Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw.
3 weeks ago
References
CVSS V3.1
Timeline
- 🦅
CISA Reported
- 🥇
Vulnerability reached the number 1 worldwide trending spot
- 📈
Vulnerability started trending
- 🟡
Public PoC available
- 💰
Used in Ransomware
- 👾
Exploit known to exist
- 📰
First article discovered by BleepingComputer
Vulnerability published
Vulnerability Reserved