Knox CVE Database
/
CVE-2026-46817
Critical
9.8

CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

Added to the CISA KEV catalog:
July 15, 2026

Overview

The File Transmission component of Oracle Payments, part of Oracle E-Business Suite, exposes a critical function over HTTP with no authentication required. An attacker who can reach the endpoint sends a direct request, with no credentials, no session and no prior interaction with the application, and takes over the Payments module outright, with full read, write and availability impact. The controls that do exist are bypassable, and the privilege model does not constrain what an unauthenticated caller can do once through. Affected releases run across the 12.2 line; instances not reachable from untrusted networks are materially lower risk.

Vulnerability details

Affected vendor
Oracle
Affected product
E-Business Suite
Weakness type (CWE)
CWE-269, CWE-287, CWE-306

The Oracle Payments File Transmission component, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15, exposes a critical function over HTTP without requiring authentication (CWE-306). The authentication controls that do exist are improperly implemented and bypassable (CWE-287), and the privilege model fails to constrain what an unauthenticated caller can do once access is obtained (CWE-269). The combination means a network-reachable instance presents no authentication barrier to an attacker who targets this component directly.


An attacker with HTTP access to the Oracle Payments File Transmission endpoint sends a direct, unauthenticated HTTP request to the component. No credentials, session token, or prior interaction with the application are required. The Oracle Payments module is fully compromised as a result, with high confidentiality, integrity, and availability impact. The Oracle Payments File Transmission component must be network-accessible via HTTP for exploitation to succeed; instances not exposed to untrusted networks have materially reduced risk. This vulnerability is listed in the CISA Known Exploited Vulnerabilities catalog, indicating confirmed active exploitation in the wild.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review Oracle E-Business Suite access logs for requests to the File Transmission component that carry no session cookie or authentication token and result in a successful HTTP response code (2xx or 3xx) rather than a 401 or 403 redirect.
  • Audit Oracle Payments transaction and audit logs for file transmission operations or privilege-level actions that have no corresponding authenticated user session in the EBS session table, indicating the action was performed outside the normal authenticated workflow.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 18, 2026

Additional hardening

  • Restrict network access to the Oracle E-Business Suite application tier so the File Transmission component is reachable only from trusted internal networks and defined user populations, not from the open internet.
  • Apply Oracle's published network access controls to limit HTTP exposure of the Oracle Payments module to specific source IP ranges; remove any public-facing load balancer rules that forward traffic to EBS application tier ports.
  • Conduct forensic triage per CISA's Forensics Triage Requirements guidance, as active exploitation is confirmed and patching alone does not address potential prior compromise.
  • Disable or restrict the File Transmission component at the application configuration level if it is not operationally required, reducing the exposed attack surface until the vendor patch is applied.

Key dates

Published (NVD)
May 28, 2026
Added to CISA KEV
July 15, 2026
Remediation deadline
July 18, 2026
Last updated
July 21, 2026

References

Frequently asked questions

Does CVE-2026-46817 affect my FedRAMP authorization?

If Oracle E-Business Suite runs inside your authorization boundary, yes — CVE-2026-46817 affects your FedRAMP authorization. CISA has listed this vulnerability in its Known Exploited Vulnerabilities catalog with a remediation deadline of July 18, 2026. An unpatched Known Exploited Vulnerability inside your boundary is an assessor finding: you either remediate it before that date or formally document a mitigation. Neither your assessor nor your sponsoring agency will let it pass without one of those two outcomes.

How does Knox help me handle CVE-2026-46817?

Remediating Oracle E-Business Suite is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, along with continuous compliance monitoring and audit-artifact coverage that document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you apply it is not something you manage on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment continuously for newly disclosed vulnerabilities and compliance issues, including cases like CVE-2026-46817. Exposure surfaces during ongoing monitoring rather than only when an assessor flags it at review time, giving your team the lead time needed to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-46817 isn't remediated by July 18, 2026?

If CVE-2026-46817 is not remediated by July 18, 2026, it becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list is precisely what turns a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization clean.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting