Security
Loading…

CVE-2026-46817

CRITICALCVSS 9.8Known Exploited
Description

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

Timeline
Published:May 28th, 2026 9:16 PM
Last modified:July 21st, 2026 10:10 AM
Added to KEV:July 15th, 2026
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Software
From NVD CPE configuration data

Vendors

oracle

Products

e-business_suite
Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute