← Back to browse · API

CVE-2026-46817

Severity
CRITICAL
CVSS
9.8
EPSS
0.13309
Risk score
68.86
CISA KEV
Yes
PoC
Yes
Published
2026-05-28
Modified
2026-07-16
First seen
2026-08-05
Aliases
EUVD-2026-33040, GHSA-PV4M-GF99-C5JR
Products
Oracle Corporation:Oracle Payments 12.2.3 ≤12.2.15, Oracle:E-Business Suite, oracle:e-business_suite, unix
Sources
nvd CVE-2026-46817
cisa.gov CVE-2026-46817
packetstorm dc096bdf06e0b40d6c432533|CVE-2026-46817
euvd EUVD-2026-33040

Description

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

References