PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46823 Oracle Corporation CVE debrief

A high-severity authorization vulnerability in Oracle Public Sector Financials (International) allows low-privileged attackers with network access to gain unauthorized access to critical data across Oracle E-Business Suite. The vulnerability affects versions 12.2.6 through 12.2.15 and carries a CVSS 3.1 score of 7.7. The scope change indicator (S:C) suggests successful exploitation may impact additional products beyond the vulnerable component.

Vendor
Oracle Corporation
Product
Oracle Public Sector Financials (International)
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-07-21
Advisory published
2026-05-28
Advisory updated
2026-07-21

Who should care

Organizations running Oracle E-Business Suite with Public Sector Financials (International) versions 12.2.6-12.2.15, particularly government and public sector entities, financial administrators, and Oracle EBS security teams responsible for maintaining authorization controls and data access governance.

Technical summary

The vulnerability exists in the Authorization component of Oracle Public Sector Financials (International), a module within Oracle E-Business Suite. The flaw allows low-privileged authenticated attackers to exploit the authorization mechanism over HTTPS, resulting in unauthorized access to critical data. The CVSS scope change metric (S:C) indicates that successful attacks may extend beyond the vulnerable component to affect additional products within the Oracle E-Business Suite environment. The vulnerability is rated HIGH severity with a base score of 7.7, primarily impacting confidentiality with no integrity or availability impacts.

Defensive priority

HIGH

Recommended defensive actions

  • Apply Oracle Critical Patch Update (CPU) for May 2026 as soon as available
  • Review and restrict HTTPS access to Oracle Public Sector Financials (International) components
  • Audit user privileges and implement principle of least privilege for E-Business Suite accounts
  • Monitor for unauthorized data access attempts across Oracle E-Business Suite products
  • Validate scope of impact given S:C CVSS metric indicating potential cross-product effects

Evidence notes

Oracle Critical Patch Update advisory published May 2026. NVD record received 2026-05-28. No known exploitation in the wild (KEV: false).

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46823 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46823

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46823 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46823

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.