PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46837 Oracle Corporation CVE debrief

A critical SQL injection vulnerability in Oracle Flow Manufacturing (Oracle E-Business Suite component: Security) allows low-privileged attackers with network access to achieve complete system takeover. Affected versions span 12.2.9 through 12.2.15. The vulnerability is rated CVSS 3.1 8.8 (High) with network attack vector, low attack complexity, and low privileges required—making it easily exploitable with severe confidentiality, integrity, and availability impacts. Oracle published security guidance in May 2026. Organizations should prioritize patching and restrict SQL network access pending remediation.

Vendor
Oracle Corporation
Product
Oracle Flow Manufacturing
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-28
Original CVE updated
2026-07-21
Advisory published
2026-05-28
Advisory updated
2026-07-21

Who should care

Organizations running Oracle E-Business Suite Flow Manufacturing module versions 12.2.9-12.2.15; database administrators; application security teams; compliance officers tracking Oracle patch status

Technical summary

Oracle Flow Manufacturing in Oracle E-Business Suite versions 12.2.9 through 12.2.15 contains an easily exploitable SQL injection vulnerability in its Security component. A low-privileged attacker with network access can send crafted SQL queries to compromise the application, resulting in complete takeover with high impact to confidentiality, integrity, and availability. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates network attack surface, low complexity, and no user interaction required.

Defensive priority

critical

Recommended defensive actions

  • Apply Oracle Critical Patch Update for May 2026 immediately to affected Flow Manufacturing instances
  • Restrict network access to Oracle E-Business Suite SQL interfaces to authorized administrative hosts only
  • Audit database activity logs for anomalous SQL execution from low-privileged accounts
  • Validate input sanitization on all SQL-accessible endpoints in Flow Manufacturing components
  • Review and enforce principle of least privilege for database accounts used by Oracle E-Business Suite applications

Evidence notes

Oracle is identified as the affected vendor based on reference domain evidence from [email protected]. The vulnerability affects Oracle Flow Manufacturing within Oracle E-Business Suite. CVSS vector confirms network-accessible, low-complexity, low-privilege attack path leading to complete CIA compromise.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46837 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46837

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46837 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46837

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.