CVE-2026-46817
This vulnerability affects Oracle Payments in Oracle E-Business Suite, specifically the File Transmission component. Unauthenticated attackers can exploit it over HTTP to take full control of the system, compromising confidentiality, integrity, and availability. The CVSS score is 9.8, indicating a critical risk.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Oracle E-Business Suite Payments component, versions 12.2.3 through 12.2.15, used by organizations running Oracle Payments.
Real-world impact
An attacker could take over the Oracle Payments system, gaining full control, accessing sensitive financial data, and potentially disrupting payment processing.
Why this severity
The high score reflects that the flaw allows remote exploitation without authentication, with complete compromise of confidentiality, integrity, and availability.
What to do about it
- 01Apply the Oracle-provided mitigation for the affected Oracle Payments File Transmission component as per Oracle's instructions.
- 02Verify that the mitigation has been applied and the system is no longer vulnerable.
CISA KEV required action
Timeline
- May 28, 2026 · May 28, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 15, 2026 · 21d agoConfirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- Jul 18, 2026 · 18d agoCISA remediation deadlineFederal agencies are required to remediate by this date.
- Jul 21, 2026 · 14d agoAdvisory updatedThe NVD record was last revised.
- Jul 21, 2026 · 14d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- oracle.com/security-alerts/cspumay2026…vendor advisory
- cisa.gov/known-exploited-vulnerabili…us government resource