PatchSiren cyber security CVE debrief
CVE-2026-46837 Oracle Corporation CVE debrief
A critical SQL injection vulnerability in Oracle Flow Manufacturing (Oracle E-Business Suite component: Security) allows low-privileged attackers with network access to achieve complete system takeover. Affected versions span 12.2.9 through 12.2.15. The vulnerability is rated CVSS 3.1 8.8 (High) with network attack vector, low attack complexity, and low privileges required—making it easily exploitable with severe confidentiality, integrity, and availability impacts. Oracle published security guidance in May 2026. Organizations should prioritize patching and restrict SQL network access pending remediation.
- Vendor
- Oracle Corporation
- Product
- Oracle Flow Manufacturing
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-28
- Original CVE updated
- 2026-07-21
- Advisory published
- 2026-05-28
- Advisory updated
- 2026-07-21
Who should care
Organizations running Oracle E-Business Suite Flow Manufacturing module versions 12.2.9-12.2.15; database administrators; application security teams; compliance officers tracking Oracle patch status
Technical summary
Oracle Flow Manufacturing in Oracle E-Business Suite versions 12.2.9 through 12.2.15 contains an easily exploitable SQL injection vulnerability in its Security component. A low-privileged attacker with network access can send crafted SQL queries to compromise the application, resulting in complete takeover with high impact to confidentiality, integrity, and availability. The CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) indicates network attack surface, low complexity, and no user interaction required.
Defensive priority
critical
Recommended defensive actions
- Apply Oracle Critical Patch Update for May 2026 immediately to affected Flow Manufacturing instances
- Restrict network access to Oracle E-Business Suite SQL interfaces to authorized administrative hosts only
- Audit database activity logs for anomalous SQL execution from low-privileged accounts
- Validate input sanitization on all SQL-accessible endpoints in Flow Manufacturing components
- Review and enforce principle of least privilege for database accounts used by Oracle E-Business Suite applications
Evidence notes
Oracle is identified as the affected vendor based on reference domain evidence from [email protected]. The vulnerability affects Oracle Flow Manufacturing within Oracle E-Business Suite. CVSS vector confirms network-accessible, low-complexity, low-privilege attack path leading to complete CIA compromise.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46837 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46837
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46837 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46837
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://www.oracle.com/security-alerts/cspumay2026.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.