PatchSiren cyber security CVE debrief
CVE-2026-46923 Oracle Corporation CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:01.930Z and has not been modified since then. The vulnerability is in Oracle Public Sector Financials (International), component: Authorization, affecting versions 12.2.3-12.2.15. This difficult to exploit vulnerability allows high privileged attackers with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks can result in takeover of Oracle Public Sector Financials (International). The CVSS 3.1 Base Score is 8.0 (Confidentiality, Integrity and Availability impacts). Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
- Vendor
- Oracle Corporation
- Product
- Oracle Public Sector Financials (International)
- CVSS
- HIGH 8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-21
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-07-21
- Advisory updated
- 2026-08-06
Who should care
Users of Oracle Public Sector Financials (International) versions 12.2.3-12.2.15, security teams, and administrators should review and address this vulnerability. Affected product deployments should be identified and prioritized for remediation based on operational impact and exposure. Vulnerability management and security teams should track exceptions and verify remediation evidence before closing the item. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified. Monitoring and detection capabilities should be checked for exposed assets that need extra review. Asset inventory and configuration management processes should be updated to reflect affected systems and changes made during remediation. Source tracking and incident response plans should also be reviewed and updated as necessary to address potential exploitation attempts. The security team should ensure that all affected systems are remediated and that the remediation is verified through testing and validation. The security team should also review and update incident response plans to address potential exploitation attempts. The security team should also review and update vulnerability management processes to prevent similar vulnerabilities from being exploited in the future. The security team should also review and update asset inventory and configuration management processes to prevent similar vulnerabilities from being exploited in the future. The security team should also review and update source tracking and incident response plans to address potential exploitation attempts. The security team should ensure that all affected systems are remediated and that the remediation is verified through testing and validation. The security team should also review and update incident response plans to address potential exploitation attempts. The security team should also review and update vulnerability management processes to prevent similar vulnerabilities from being exploited in the future. The security team should also review and update asset inventory and configuration management processes to prevent similar vulnerabilities from being exploited in the future.
Technical summary
Difficult to exploit vulnerability in Oracle Public Sector Financials (International) allows high privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in takeover of Oracle Public Sector Financials (International). The vulnerability affects versions 12.2.3-12.2.15 and has a CVSS 3.1 Base Score of 8.0. The vulnerability is in the Authorization component, and high privileged attackers with network access via HTTP can exploit it. The attack surface is limited to systems with network access via HTTP, and defenders should prioritize patching or mitigating affected deployments.
Defensive priority
High privileged attackers with network access via HTTP may compromise Oracle Public Sector Financials (International).
Recommended defensive actions
- Apply vendor patches or updates
- Restrict network access to Oracle Public Sector Financials (International)
- Monitor for suspicious activity
- Implement compensating controls
- Inventory and verify affected systems
Evidence notes
The vulnerability is in Oracle Public Sector Financials (International), component: Authorization, affecting versions 12.2.3-12.2.15. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). Evidence is limited to CVE and NVD details. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.
Official resources
-
CVE-2026-46923 CVE record
CVE.org
-
CVE-2026-46923 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-21T22:17:01.930Z and has not been modified since then.