PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46828 Oracle Corporation CVE debrief

A high-severity vulnerability in Oracle E-Business Suite's Payroll component (Internal Operations) allows low-privileged attackers with network access to compromise Oracle Payroll via HTTP. The vulnerability, published on 2026-05-28, affects supported versions 12.2.3 through 12.2.15. Successful exploitation can result in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all Oracle Payroll accessible data. The CVSS 3.1 base score of 8.1 reflects high impacts to confidentiality and integrity, with no availability impact. The attack vector is network-based, requires low attack complexity, low privileges, and no user interaction. Oracle has published security guidance in their May 2026 Critical Patch Update.

Vendor
Oracle Corporation
Product
Oracle Payroll
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-07-21
Advisory published
2026-05-28
Advisory updated
2026-07-21

Who should care

Organizations running Oracle E-Business Suite versions 12.2.3-12.2.15 with the Payroll module enabled, particularly those with external network access to payroll systems or multiple users with low-privilege access to payroll functions.

Technical summary

The vulnerability exists in the Internal Operations component of Oracle Payroll within Oracle E-Business Suite. A low-privileged attacker with network access can exploit this via HTTP to gain unauthorized access and modification capabilities over critical payroll data. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) indicates network attack vector, low attack complexity, low privileges required, no user interaction, unchanged scope, and high impacts to confidentiality and integrity with no availability impact.

Defensive priority

HIGH

Recommended defensive actions

  • Apply Oracle Critical Patch Update for May 2026 as soon as available
  • Review Oracle E-Business Suite Payroll component access controls and network segmentation
  • Monitor for unauthorized access attempts to Oracle Payroll Internal Operations endpoints
  • Validate that only necessary HTTP access to Payroll components is permitted
  • Review audit logs for suspicious data modification or access patterns in Oracle Payroll

Evidence notes

The vulnerability description is sourced from NVD with reference to Oracle's official security alert. Vendor attribution to Oracle is based on reference domain evidence with low confidence flag for review. The affected product is Oracle E-Business Suite Payroll component, specifically Internal Operations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46828 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46828

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46828 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46828

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.