Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-46817: Oracle E-Business Suite Payments File Transmission Compromise
Known exploited
CVE-2026-46817
CVE-2026-46817
CVE-2026-46817
Summary
The Oracle E-Business Suite's Payments component has a vulnerability in its File Transmission feature. This means an attacker with internet access can potentially take control of the Payments system, which could lead to sensitive information being stolen, payments being manipulated, or the system being shut down. Update your system to the latest version to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| oracle | e-business suite | All versions |
| oracle | e-business_suite |
>= 12.2.3, <= 12.2.15 cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:* |
| oracle corporation | oracle payments | <= 12.2.15 |
Original title
Oracle E-Business Suite Improper Privilege Management Vulnerability
Original description
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
nvd CVSS3.1
9.8
Vulnerability type
CWE-269
Improper Privilege Management
CWE-287
Improper Authentication
CWE-306
Missing Authentication for Critical Function
Published: 15 Jul 2026 · Updated: 16 Jul 2026 · First seen: 28 May 2026