CVE-2026-46817

Published May 28, 2026

Last updated 2 months ago

Exploit knownCVSS critical 9.8
Business logic
OT
Oracle Payments
Oracle E-Business Suite

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-46817 is a vulnerability found in the File Transmission component of Oracle Payments, part of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. This flaw stems from improper privilege management, improper authentication, and a lack of authentication for a critical function. It can be exploited remotely over HTTP without requiring authentication or user interaction, specifically targeting the `/OA_HTML/ibytransmit` endpoint with XML payloads. Successful exploitation of CVE-2026-46817 can lead to a complete compromise of the Oracle Payments module. Observed exploitation attempts have included unauthenticated file-read operations, potentially exposing sensitive system files like `/etc/passwd` and configuration files containing database credentials, encryption keys, and payment-processor API keys. The vulnerability has been added to CISA's Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild, and Oracle released patches for it in May 2026.

Description
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Source
secalert_us@oracle.com
NVD status
Analyzed
Products
e-business_suite

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Oracle E-Business Suite Improper Privilege Management Vulnerability
Exploit added on
Jul 15, 2026
Exploit action due
Jul 18, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-269

Social media

Hype score
Not currently trending
  1. CISA KEV: Oracle EBS Payments CVE-2026-46817 (due July 18). Unauth HTTP can take over Oracle Payments (CVSS 9.8). Affects 12.2.3-12.2.15. Apply the May 2026 CSPU now; treat exposed Payments as urgent. https://t.co/1JQCWvyvA1 #CVE #CyberSecurity

    @snypet86

    5 Aug 2026

    56 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2026-46817: Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild 0day Intel: Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild https

    @lyrie_ai

    19 Jul 2026

    66 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. 07:59 UTC: CVE-2026-46817 disclosed. Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild 0day Intel: Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild https

    @lyrie_ai

    19 Jul 2026

    63 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. 06:36 UTC: CVE-2026-46817 disclosed. Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild 0day Intel: Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild https

    @lyrie_ai

    19 Jul 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  5. CVE-2026-46817. 0day Intel: #CVE-2026-46817 — #Oracle #EBS Payments #RCE Exploit Kit

    @lyrie_ai

    19 Jul 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  6. 🚨 CISA KEV Deadlines This Week 📅 Jul 17: SonicWall SMA1000 SSRF (CVE-2026-15409, CVSS 10.0) + Code Injection (CVE-2026-15410) | Microsoft SharePoint Missing Auth (CVE-2026-56164, CVSS 9.8) 📅 Jul 18: Oracle E-Business Suite Improper Privilege Management (CVE-2026-46817,

    @techepages

    18 Jul 2026

    76 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. 🔒 #CyberSecurity CVE-2026-46817 & CVE-2023-4346: CISA KEV Alert — Oracle EBS & KNX Protocol Acti… "On July 15, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added two…" 🔗 https://t.co/OFLZjv0KBe #CyberSecurity #ThreatIntel #cve #zeroday

    @SecurityAr58409

    16 Jul 2026

    88 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 Over 900 Oracle E-Business Suite instances exposed online amid active exploitation of critical flaw CVE-2026-46817 (CVSS 9.8), unauthenticated HTTP takeover, no privileges needed. 🔹 Flaw sits in Payments' File Transmission component; patched in May 2026 CPU 🔹 First

    @techepages

    1 Jul 2026

    92 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Oracle-E-Business-Suite(EBS)のOracle-Payments製品に含まれるFile-Transmissionコンポーネントの脆弱性CVE-2026-46817(CVSS-9.8)が、公開PoCが存在しないなかで実悪用され始めたと報告されています。未認証の攻撃者がHTTPネッ

    @MalwareBibleJP

    1 Jul 2026

    966 Impressions

    0 Retweets

    8 Likes

    1 Bookmark

    0 Replies

    1 Quote

  10. Top exploited KEVs we tracked over the past 7 days: 1 CVE-2025-61882 - Oracle EBS 2 CVE-2026-10520 - Ivanti Sentry 3 CVE-2022-47945 - ThinkPHP 4 CVE-2026-20230 - Cisco UCM 5 CVE-2026-46817 - Oracle EBS 6 CVE-2026-20253 - Splunk

    @kev_intel

    1 Jul 2026

    239 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Legacy exposure keeps paying off for attackers. Oracle E-Business Suite CVE-2026-46817 is now an active e… CVE-2026-46817 is a critical Oracle Payments flaw in Oracle E-Business Suite. Active exploi… 🔗 Read → https://t.co/Dc2bPn5FcM

    @fynn_JourX

    30 Jun 2026

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🛑 Oracle E-Business Suite CVE-2026-46817 is now an active exploitation ri… CVE-2026-46817 is a critical Oracle Payments flaw in Oracle E-Business Suite. Active exploi… 🔗 Details → https://t.co/mGq2ENNdvX

    @lucasverdan

    30 Jun 2026

    111 Impressions

    1 Retweet

    1 Like

    1 Bookmark

    0 Replies

    0 Quotes

  13. It's Already When. — Field Note Active exploitation hits SimpleHelp (CVE-2026-48558) and Oracle EBS (CVE-2026-46817), while a public PoC drops for the libssh2 client fla... https://t.co/IaHFrXvk3x #CyberSecurity #ThreatIntel

    @itsalreadywhen

    30 Jun 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Oracle EBS CVE-2026-46817 (CVSS 9.8) is being actively exploited. Unauthenticated HTTP takeover of the Payments component. 450+ instances exposed online. No POC needed. Same playbook Clop used against Harvard & WaPo in 2025. Salt can find these unauthenticated endpoints be

    @SaltSecurity

    29 Jun 2026

    152 Impressions

    3 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. مهاجمان سایبری بهره‌برداری فعال از یک آسیب‌پذیری بحرانی با شناسه CVE-2026-46817 را در نرم‌افزار مالی Oracle E-Business Suite (EBS) آغاز کرده‌اند. این نقص امنیتی که در مؤلف

    @Teeegra

    29 Jun 2026

    695 Impressions

    0 Retweets

    14 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  16. Warning: Critical #vulnerabilities in #Oracle REST Data Services & E-Business Suite allow system takeover. #CVE-2026-46840 CVSS(3.1): 10.0 | #CVE-2026-46817 CVSS(3.1): 9.8. Part of a larger Oracle patch update. Read our advisory at https://t.co/ejRAvBZxGo and #Patch #Patch #P

    @CCBalert

    29 May 2026

    147 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations