PT-2026-44513 · Oracle · Oracle Payments
CVE-2026-46817
·
Published
2026-05-28
·
Updated
2026-07-21
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oracle Payments for Oracle E-Business Suite versions 12.2.3 through 12.2.15
Description
An improper privilege management and authentication flaw exists in the File Transmission component of Oracle Payments. This issue allows an unauthenticated remote attacker with network access via HTTP to compromise the system, potentially leading to a full takeover of the application and the ability to read arbitrary files from the server. The flaw is attributed to improper input validation in an HTTP-exposed endpoint that processes file transmission requests. There are over 1,000 internet-exposed instances tracked globally, with more than half located in the United States. This issue has been actively exploited in the wild, with attack activity captured across honeypot infrastructure.
Recommendations
Apply the Oracle May 2026 Critical Security Patch Update or the specific one-off fix for this issue for versions 12.2.3 through 12.2.15.
Restrict internet exposure of Oracle Payments environments to minimize the risk of exploitation.
Fix
RCE
LPE
Improper Authentication
Improper Privilege Management
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Payments