


Perceptive Security
SOC/SIEM Consultancy

Vulnerability in the Oracle iAssets product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.1…
Published:
27 May 2026 at 22:00:00
Alert date:
28 May 2026 at 22:04:22
Source:
nvd.nist.gov
Enterprise Applications
Critical vulnerability in Oracle iAssets component of Oracle E-Business Suite affecting versions 12.2.3-12.2.15. The easily exploitable flaw allows low privileged attackers with network access via HTTP to completely compromise Oracle iAssets. Successful exploitation can result in full system takeover with high impact to confidentiality, integrity, and availability. The vulnerability has scope change potential, meaning attacks may significantly impact additional products beyond Oracle iAssets. CVSS 3.1 Base Score of 9.9 indicates critical severity.
Technical details
Mitigation steps:
Affected products:
Oracle iAssets
Oracle E-Business Suite
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-46822
https://www.oracle.com/security-alerts/cspumay2026.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
