CVE-2026-46817 · High · CISA KEV
Oracle E-Business Suite Payments Vulnerability: Unauthenticated Takeover Risk
Threat Engine Auto-Feed · data current as of 2026-07-15
CVE-2026-46817, an improper privilege management vulnerability in Oracle E-Business Suite, allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. This vulnerability is actively exploited in the wild, as indicated by its inclusion in CISA KEV.
- CVSS:
- EPSS percentile: 0.48111
- Exploitation pressure: 54/100 (High)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 48th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
Improper privilege management occurs when a system or application does not correctly restrict or manage the permissions granted to users or processes. This can allow an attacker to gain elevated privileges or perform actions they should not be authorized to do, potentially leading to full system compromise or unauthorized data access.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations utilizing Oracle E-Business Suite, particularly those with Oracle Payments deployed.
- Financial services and retail sectors, due to the nature of the compromised module and historical targeting by relevant threat actors.
Misconfigurations that escalate it
- Any configuration that exposes Oracle E-Business Suite to unauthenticated network access via HTTP.
High-impact scenarios
- An unauthenticated attacker gaining full control over Oracle Payments, potentially leading to financial fraud, data theft, and disruption of payment processing.
- Compromise of sensitive financial data and payment infrastructure, with a broad blast radius affecting customer trust and regulatory compliance.
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor network traffic for unusual access patterns to Oracle E-Business Suite, especially HTTP requests targeting Oracle Payments.
- Review Oracle E-Business Suite logs for unauthorized privilege escalation attempts or suspicious activities within the Oracle Payments module.
- Scan for unpatched Oracle E-Business Suite instances.
Contain
- Isolate affected Oracle E-Business Suite instances from the network if compromise is suspected.
- Block suspicious IP addresses attempting to access Oracle E-Business Suite via HTTP.
Patch
- Apply the latest security patches from Oracle for E-Business Suite to address CVE-2026-46817.
Frontier verdict — High
High priority due to active exploitation in the wild (CISA KEV) and potential for unauthenticated takeover of Oracle Payments.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.