LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jul 15, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jul 18, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-46817 to its Known Exploited Vulnerabilities catalog on Jul 15, 2026, with a federal patch deadline of Jul 18, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks…

This vulnerability affects Oracle E-Business Suite and permits an unauthenticated attacker with network access via HTTP to compromise the Oracle Payments component, resulting in full takeover of that module. The issue stems from weaknesses in privilege management and authentication controls that should restrict access to payment functions.

How it works

The flaw class centers on improper privilege management (CWE-269), authentication problems (CWE-287), and missing authentication for critical functions (CWE-306). An attacker reaches the affected component over HTTP without supplying credentials and can elevate actions to control Oracle Payments.

Successful exploitation grants the attacker the ability to perform operations that should require authenticated and authorized sessions. No further details on request construction or payload behavior are provided in the available summary.

Am I affected? How to find it in your systems

Oracle E-Business Suite instances that expose the Payments module to network HTTP traffic are the primary concern. Inventory all deployments of the product, identify any internet-facing or internally reachable Payments endpoints, and note configurations that permit unauthenticated access.

How to remediate

Apply the vendor update referenced in the official advisory as the primary step. After patching, review authentication and authorization settings for the Payments component to ensure they align with least-privilege principles.

If you can't patch immediately

Apply mitigations in accordance with vendor instructions while complying with CISA BOD 26-04 guidance on prioritizing security updates. Segment networks so that HTTP traffic to Oracle Payments originates only from trusted sources.

If your data may have been exposed

Successful exploitation of this class of vulnerability can lead to unauthorized control of payment functions and subsequent data exposure. Organizations should review access and transaction logs for indicators of compromise and run a free exposure scan of their email addresses against known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedOracle · E-Business Suite
WeaknessCWE-269
Added to CISA KEVJul 15, 2026
Federal patch deadlineJul 18, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities