Unauthenticated Vulnerability in Oracle Payments of Oracle E-Business Suite
CVE-2026-46818

7.4HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 May 2026

What is CVE-2026-46818?

An unauthenticated vulnerability has been identified in the Oracle Payments component of the Oracle E-Business Suite, specifically affecting several supported versions. This flaw allows an attacker with network access via HTTPS to potentially compromise the Oracle Payments system. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, as well as access to sensitive information within the Oracle Payments application. Organizations should implement immediate security measures to mitigate risks associated with this vulnerability.

Affected Version(s)

Oracle Payments 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.