Vulnerability in Oracle iAssets Affects Oracle E-Business Suite
CVE-2026-46822

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 May 2026

What is CVE-2026-46822?

A vulnerability exists in the Oracle iAssets product of the Oracle E-Business Suite, specifically within its internal operations component. This vulnerability allows an attacker with low-level privileges and network access via HTTP to compromise Oracle iAssets. The exploitation of this vulnerability not only affects Oracle iAssets but can also lead to significant impacts on other interconnected products. Successfully executing an attack can result in the complete takeover of Oracle iAssets, posing risks to confidentiality, integrity, and availability across the suite.

Affected Version(s)

Oracle iAssets 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.