PT-2026-44513 · Oracle · Oracle Payments

CVE-2026-46817

·

Published

2026-05-28

·

Updated

2026-07-21

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Payments for Oracle E-Business Suite versions 12.2.3 through 12.2.15
Description An improper privilege management and authentication flaw exists in the File Transmission component of Oracle Payments. This issue allows an unauthenticated remote attacker with network access via HTTP to compromise the system, potentially leading to a full takeover of the application and the ability to read arbitrary files from the server. The flaw is attributed to improper input validation in an HTTP-exposed endpoint that processes file transmission requests. There are over 1,000 internet-exposed instances tracked globally, with more than half located in the United States. This issue has been actively exploited in the wild, with attack activity captured across honeypot infrastructure.
Recommendations Apply the Oracle May 2026 Critical Security Patch Update or the specific one-off fix for this issue for versions 12.2.3 through 12.2.15. Restrict internet exposure of Oracle Payments environments to minimize the risk of exploitation.

Fix

RCE

LPE

Improper Authentication

Improper Privilege Management

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08976
CVE-2026-46817

Affected Products

Oracle Payments