Internal Operations Vulnerability in Oracle Public Sector Payroll
CVE-2026-46976

7.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46976?

A vulnerability exists in the Oracle Public Sector Payroll component of the Oracle E-Business Suite, specifically within its Internal Operations. This flaw manifests in supported versions 12.2.3 to 12.2.15 and can be exploited by an attacker with high privileges and network access via HTTP. If successfully exploited, the vulnerability could enable the attacker to take control of the Oracle Public Sector Payroll application, jeopardizing sensitive data and operational integrity. Stakeholders should prioritize remediation and ensure that security best practices are followed to mitigate this risk.

Affected Version(s)

Oracle Public Sector Payroll 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.