Vulnerability in Oracle Financials Common Modules of Oracle E-Business Suite
CVE-2026-46820

8.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 May 2026

What is CVE-2026-46820?

A vulnerability exists in the Oracle Financials Common Modules of the Oracle E-Business Suite affecting versions 12.2.3 to 12.2.15. This easily exploitable flaw allows low-privileged attackers with network access via HTTP to compromise sensitive components of the Oracle Financials system. Successful exploitation can result in unauthorized access to critical data and enable attackers to perform unauthorized actions such as data updates or deletions. The impact of this vulnerability extends beyond the common modules, potentially affecting other integrated products, thereby threatening overall data security and integrity.

Affected Version(s)

Oracle Financials Common Modules 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.