---
id: CVE-2026-46817
title: >-
  Vulnerability in the Oracle Payments product of Oracle E-Business Suite
  (component: File Transmission)
summary: >-
  Vulnerability in the Oracle Payments product of Oracle E-Business Suite
  (component: File Transmission).  Supported versions that are affected are
  12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated
  attacker with netwo…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
  - CWE-287
  - CWE-306
vendor: oracle
product: e-business_suite
affected:
  - 'e-business_suite >= 12.2.3, <= 12.2.15'
published: '2026-05-28'
updated: '2026-07-15'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-46817'
references:
  - url: 'https://www.oracle.com/security-alerts/cspumay2026.html'
    label: secalert_us@oracle.com
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-46817
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.00814
epssPercentile: 0.55219
kev: true
kevDateAdded: '2026-07-15'
kevDueDate: '2026-07-18'
kevRansomware: false
exploited: true
ingestedAt: '2026-07-16T02:48:55.015Z'
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/0xBlackash/CVE-2026-46817'
    - 'https://github.com/HORKimhab/CVE-2026-46817'
  checkedAt: '2026-09-26T09:05:45.001Z'
exploitAvailable: true
---

## Overview

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments.  Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

## Affected

- `e-business_suite >= 12.2.3, <= 12.2.15`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
