
CVE-2026-46817
Critical unauthenticated remote vulnerability affecting Oracle Payments (File Transmission) that may allow complete compromise of the application over HTTP.
CVE-2026-46817 is a critical vulnerability in the Oracle Payments component of Oracle E-Business Suite. The flaw affects the File Transmission functionality and can be exploited remotely over HTTP without authentication.
A successful attack may allow an attacker to fully compromise the vulnerable Oracle Payments application, resulting in complete loss of:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
| Product | Affected Versions |
|---|---|
| Oracle E-Business Suite | 12.2.3 – 12.2.15 |
| Component | Oracle Payments – File Transmission |
Successful exploitation could allow an attacker to:
Oracle recommends applying the latest Critical Patch Update (CPU) immediately.
Additional defensive measures include:
Security teams should monitor for:
Security is a process, not a product.
| Metric | Value |
|---|
| CVE ID | CVE-2026-46817 |
| CVSS v3.1 | 9.8 (Critical) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Item |
|---|
| Status |
|---|
| Severity | 🔴 Critical |
| CVSS | 9.8 |
| Remote | ✅ Yes |
| Authentication Required | ❌ No |
| User Interaction | ❌ No |
| Patch Available | ✅ Yes |