Vulnerability in Oracle Financials Common Modules of Oracle E-Business Suite
CVE-2026-46821

7.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 May 2026

What is CVE-2026-46821?

An improper access control vulnerability exists in Oracle Financials Common Modules within the Oracle E-Business Suite, affecting supported versions 12.2.3 to 12.2.15. This flaw allows low-privileged attackers with network access over HTTP to gain unauthorized access to sensitive data associated with Oracle Financials Common Modules. The attacks can extend their impact on various interconnected products. Successful exploitation can lead to significant unauthorized data exposure, highlighting the need for prompt action to mitigate potential risks.

Affected Version(s)

Oracle Financials Common Modules 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.