


Perceptive Security
SOC/SIEM Consultancy

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 22:04:22
Source:
nvd.nist.gov
Enterprise Applications
Critical vulnerability in Oracle Payments component of Oracle E-Business Suite affecting File Transmission functionality. Affects versions 12.2.3-12.2.15. Allows unauthenticated attackers with network access via HTTP to completely compromise Oracle Payments. CVSS score of 9.8 indicates maximum impact on confidentiality, integrity, and availability. The vulnerability is easily exploitable and can result in complete system takeover. No user interaction required for exploitation. Attack vector is network-based with low attack complexity.
Technical details
Mitigation steps:
Affected products:
Oracle Payments
Oracle E-Business Suite
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-46817
https://www.oracle.com/security-alerts/cspumay2026.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
