oM noM Security Feeds cve
vulnerability context

CVE-2026-46817

CVSS 9.8 CRITICALEPSS 34%CWE-269OTX 9 pulses

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Published 2026-05-28 · last modified 2026-06-17

details

CISA KEV status
Not in catalog
CVSS v3
9.8 / CRITICAL
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
34% percentile (score 0.0042)
CWE
CWE-269
OTX pulses
9 total, 0 recent

source mentions 4

source consensus

  • Bluesky
  • BleepingComputer
  • Bluesky:@cyberhub.blog
Want the 3-bullet summary of CVE-2026-46817, plus webhook alerts when KEV is updated? Pro is $10/mo.