Oracle E-Business Suite takeover (CVE-2026-46817) [PoC]
CVE-2026-46817
CVE-2026-46817: Oracle E-Business Suite Oracle Payments unauthenticated takeover, CVSS 9.8, actively exploited. Update to 12.2.16 or later; mitigate via network controls.
Actively exploited in the wild - CVE-2026-46817 is a critical vulnerability in Oracle E-Business Suite (EBS) versions 12.2.3-12.2.15 that lets an unauthenticated attacker fully compromise Oracle Payments. CISA has confirmed active exploitation, making this vulnerability an urgent patching priority.
Overview
CVE-2026-46817 affects the Oracle Payments product within Oracle E-Business Suite, specifically the File Transmission component. An attacker can exploit this vulnerability over HTTP without needing any credentials or user interaction. Successful exploitation grants the attacker complete control over the Oracle Payments application, impacting the confidentiality, integrity, and availability of all data processed by the service.
The vulnerability carries a CVSS 3.1 base score of 9.8 (CRITICAL), reflecting the low complexity of the attack, the network-based attack vector, and the full “takeover” impact. While the EPSS probability score is low (0.7%), the confirmation of active exploitation by CISA elevates the risk significantly for affected organizations.
Affected Versions
- Oracle E-Business Suite versions 12.2.3 through 12.2.15 Oracle Payments product is vulnerable.
Remediation and Mitigation
Patch: Apply the Oracle Critical Patch Update (CPU) released for this CVE. Update Oracle E-Business Suite to the latest patched version (12.2.16 or later) immediately.
Mitigation (if patching is delayed):
- Restrict HTTP access to Oracle Payments servers to trusted IP ranges and internal networks only.
- Monitor network traffic patterns for unauthorized or suspicious HTTP requests to the Oracle Payments component.
- Implement Web Application Firewall (WAF) rules to block known attack patterns.
Security Insight
Oracle E-Business Suite has been a persistent target for both commodity and targeted threat actors, with incidents like the Oracle WebLogic CVE-2024-21182 exploited in the wild reinforcing that unauthenticated network-access vulnerabilities in Oracle middleware are a favored vector. This CVE follows that trend, highlighting the risk of leaving even older versions of the File Transmission component exposed. Attackers are likely chaining this vulnerability with lateral movement techniques to pivot from the application layer to the broader enterprise network, making timely patching critical for preventing a full breach.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| 0xBlackash/CVE-2026-46817 CVE-2026-46817 | ★ 1 |
| HORKimhab/CVE-2026-46817 CVE-2026-46817 - Draft | ★ 0 |
Showing 2 of 2 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ directo...
NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address r...
Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execution via pull requests from forked repositories. Due...
The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This is due to a broken validation check in the bundled listee-core plugin's user regi...