Oracle E-Business Suite file transfer flaw under attack

Published July 15, 2026 CVE-2026-46817

Oracle E-Business Suite lets attackers send specially built files to the payment system's file transfer feature, which can crash it or let them run their own commands. This affects the File Transmission part of Oracle Payments, used for sending and receiving payment files like bank transfers or invoices.

Severity
CriticalCVSS 3.1 ยท 9.8
Fix
Fixed in 12.2.15Fix recorded on Aug 26, 2026
Affected versions
12.2.3 through 12.2.15
Weakness
CWE-269Improper Privilege Management
Exploit likelihood
13% in 30 daysEPSS, higher than 96% of known flaws
Affects
Oracle Payments
Exploited
Yes, in the wildListed by CISA
Added to CISA list
Jul 15, 2026
Federal fix deadline
Jul 18, 2026

What to do

Check the installed Oracle Payments version. This advisory applies to 12.2.15 or earlier.

Update Oracle Payments to 12.2.15 or newer. Then verify the installed version.

Technical details

An attacker sends a fake payment file with broken data to the File Transmission feature. The system tries to read it but crashes instead. In some cases, the attacker can trick the system into running commands they control on the server.

A critical vulnerability in the File Transmission component of Oracle Payments (part of Oracle E-Business Suite) allows unauthenticated attackers to fully compromise the system over HTTP. The flaw affects supported versions 12.2.3 through 12.2.15, enabling attackers to take complete control of Oracle Payments, disrupting operations, stealing data, or deploying malicious payloads. The vulnerability scores CVSS 3.1 Base Score 9.8, with high impact on confidentiality, integrity, and availability.

Attackers require no prior access or user interaction to exploit this weakness. CVE-2026-46817.

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required None Attacker needs no account or login
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact High Sensitive data can be exposed with serious impact
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator