Knox CVE Database
/
CVE-2026-46817
Critical
9.8

CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

Added to the CISA KEV catalog:
July 15, 2026

Overview

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Vulnerability details

Affected vendor
Oracle
Affected product
E-Business Suite
Weakness type (CWE)
CWE-269, CWE-287, CWE-306

The Oracle Payments File Transmission component in E-Business Suite versions 12.2.3 through 12.2.15 exposes a critical function over HTTP without requiring authentication (CWE-306, CWE-287). Once reached, the component fails to enforce appropriate privilege boundaries (CWE-269), meaning any request that arrives at the endpoint is processed with elevated privileges. This combination places a high-value financial processing function within reach of any network-adjacent party, with no credential barrier between the attacker and administrative-level operations.

An attacker with HTTP access to the Oracle Payments File Transmission endpoint sends crafted requests requiring no credentials or prior session establishment. Because the endpoint performs no authentication check and grants elevated privileges to the caller, the attacker gains full administrative control over the Oracle Payments module. The precondition is straightforward: the File Transmission component must be reachable over the network. Organizations that expose E-Business Suite HTTP interfaces directly to untrusted networks face the highest risk, as exploitation requires no user interaction and no special knowledge beyond network access.

Severity and impact

9.8
Critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review Oracle E-Business Suite HTTP access logs for requests to File Transmission component endpoints originating from sources outside your defined EBS client IP ranges, particularly sessions with no associated authenticated user record.
  • Audit Oracle Payments transaction and audit logs for privileged operations (file transmission jobs initiated, payment records modified) that have no corresponding authenticated session or user login event in the EBS application audit trail.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
July 18, 2026

Additional hardening

  • Restrict network access to Oracle E-Business Suite HTTP interfaces using firewall rules, permitting only known, authorized client IP ranges.
  • Disable or remove the File Transmission component from internet-facing EBS instances if the functionality is not operationally required.
  • Place Oracle E-Business Suite behind a reverse proxy or WAF configured to require authentication before passing requests to Payments endpoints.
  • Conduct forensic triage per CISA guidance to identify unauthorized Payments activity prior to patching, given confirmed active exploitation.

Key dates

Published (NVD)
May 28, 2026
Added to CISA KEV
July 15, 2026
Remediation deadline
July 18, 2026
Last updated
July 21, 2026

References

Frequently asked questions

Does CVE-2026-46817 affect my FedRAMP authorization?

If Oracle E-Business Suite runs inside your authorization boundary, yes. CVE-2026-46817 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of July 18, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-46817?

Knox doesn't patch your software for you — remediating Oracle E-Business Suite is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-46817 isn't remediated by July 18, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting