PatchSiren cyber security CVE debrief
CVE-2026-46820 Oracle Corporation CVE debrief
A high-severity vulnerability in Oracle E-Business Suite's Financials Common Modules allows low-privileged attackers with network access to compromise confidentiality and integrity of critical data across affected systems.
- Vendor
- Oracle Corporation
- Product
- Oracle Financials Common Modules
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-07-21
Who should care
Organizations running Oracle E-Business Suite Financials Common Modules versions 12.2.3-12.2.15, particularly those with externally accessible deployments or large user bases with low-privilege accounts. Security teams should prioritize patching due to the easily exploitable nature and high confidentiality impact.
Technical summary
The vulnerability exists in the Common Components module of Oracle Financials Common Modules. A low-privileged attacker with network access via HTTP can exploit this weakness to gain unauthorized access to critical data or complete access to all accessible data within the module, plus unauthorized modification capabilities. The scope change (S:C) indicates attacks may significantly impact additional products beyond the vulnerable component itself. No availability impact is indicated.
Defensive priority
HIGH
Recommended defensive actions
- Apply Oracle Critical Patch Update for May 2026 as soon as possible
- Restrict network access to Oracle E-Business Suite Financials Common Modules to authorized users and systems
- Monitor for unauthorized access attempts to Financials Common Modules components
- Review access logs for anomalous data access patterns indicating potential exploitation
- Validate that scope change protections are in place to prevent lateral impact to additional Oracle products
Evidence notes
The vulnerability is rated CVSS 3.1 8.5 (HIGH) with network attack vector, low attack complexity, low privileges required, no user interaction, and scope change indicating impact beyond the vulnerable component. Confidentiality impact is rated HIGH and integrity impact LOW.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46820 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46820
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46820 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46820
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspumay2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.