SYS::ONLINE
Wasteland.
Briefs1263
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-46817 2026-07-15

CVE-2026-46817: Critical Oracle E-Business Suite Flaw Enables Full Takeover of Oracle Payments

"CISA has added CVE-2026-46817, a critical (CVSS 9.8) improper privilege management flaw in Oracle E-Business Suite, to its Known Exploited Vulnerabilities catalog, confirming active exploitation and setting a July 18…"

CISA has added CVE-2026-46817, a critical (CVSS 9.8) improper privilege management flaw in Oracle E-Business Suite, to its Known Exploited Vulnerabilities catalog, confirming active exploitation and setting a July 18, 2026 remediation deadline.

What Is It

CVE-2026-46817 is a vulnerability in the Oracle Payments product of Oracle E-Business Suite, specifically the File Transmission component. It is easily exploitable, allowing an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks can result in a complete takeover of Oracle Payments. The flaw is associated with three weakness types: improper privilege management (CWE-269), improper authentication (CWE-287), and missing authentication for a critical function (CWE-306).

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL) with the vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, meaning it is network-exploitable with low complexity, requires no privileges or user interaction, and inflicts high impact on confidentiality, integrity, and availability. CISA's SSVC assessment rates exploitation as "active," automatability as "yes," and technical impact as "total." CISA added it to the KEV catalog on July 15, 2026, confirming active exploitation in the wild.

What's Vulnerable

Oracle E-Business Suite, Oracle Payments product (File Transmission component). Supported versions affected are 12.2.3 through 12.2.15. Known ransomware campaign use is listed as Unknown.

Patch Status

CISA requires organizations to apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and CISA's "Forensics Triage Requirements." For cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders must evaluate each asset's internet exposure and adhere to BOD 26-04 patching guidelines. The remediation due date is July 18, 2026. Vendor fixes are addressed in Oracle's May 2026 Critical Patch Update.

Sources