Vulnerability in Oracle iSupplier Portal Affects Oracle E-Business Suite
CVE-2026-46894

8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46894?

A vulnerability exists in the Oracle iSupplier Portal component of the Oracle E-Business Suite that allows a low-privilege attacker to compromise the portal through network access over HTTPS. Exploitation of this vulnerability necessitates user interaction from an unwitting individual, which can lead to significant security risks including the potential takeover of the portal. Users must be vigilant and apply any available patches or workarounds to mitigate this risk. For detailed guidance, refer to the Oracle Advisory.

Affected Version(s)

Oracle iSupplier Portal 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.