CVE-2026-46817
exploitation · critical · Evidence score 90
- Vendor
- Oracle
- Affected software
- Oracle E-Business Suite
- Exploitation signal
- Listed in CISA Known Exploited Vulnerabilities
- EPSS
- 0.13309
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
Provenance
CISA Known Exploited Vulnerabilities
15 July 2026, 10:00 AM AEST