Vulnerability in Oracle E-Business Suite Cost Management
CVE-2026-46938

7.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46938?

The vulnerability affects the Cost Management component of Oracle's E-Business Suite, specifically versions 12.2.3 to 12.2.15. This flaw allows an attacker with elevated privileges and network access via HTTP to execute unauthorized actions, potentially leading to full control over the Cost Management system. The ease of exploitation raises significant security concerns for organizations utilizing these versions.

Affected Version(s)

Oracle Cost Management 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.