Oracle E-Business Suite file transfer flaw under attack
Oracle E-Business Suite lets attackers send specially built files to the payment system's file transfer feature, which can crash it or let them run their own commands. This affects the File Transmission part of Oracle Payments, used for sending and receiving payment files like bank transfers or invoices.
- Severity
- CriticalCVSS 3.1 ยท 9.8
- Fix
- Fixed in 12.2.15Fix recorded on Aug 26, 2026
- Affected versions
- 12.2.3 through 12.2.15
- Weakness
- CWE-269Improper Privilege Management
- Exploit likelihood
- 13% in 30 daysEPSS, higher than 96% of known flaws
- Affects
- Oracle Payments
- Exploited
- Yes, in the wildListed by CISA
- Added to CISA list
- Jul 15, 2026
- Federal fix deadline
- Jul 18, 2026
What to do
Check the installed Oracle Payments version. This advisory applies to 12.2.15 or earlier.
Update Oracle Payments to 12.2.15 or newer. Then verify the installed version.
Technical details
An attacker sends a fake payment file with broken data to the File Transmission feature. The system tries to read it but crashes instead. In some cases, the attacker can trick the system into running commands they control on the server.
A critical vulnerability in the File Transmission component of Oracle Payments (part of Oracle E-Business Suite) allows unauthenticated attackers to fully compromise the system over HTTP. The flaw affects supported versions 12.2.3 through 12.2.15, enabling attackers to take complete control of Oracle Payments, disrupting operations, stealing data, or deploying malicious payloads. The vulnerability scores CVSS 3.1 Base Score 9.8, with high impact on confidentiality, integrity, and availability.
Attackers require no prior access or user interaction to exploit this weakness. CVE-2026-46817.
Severity breakdown
- Attack vector Network Requires network access to the vulnerable service
- Attack complexity Low Low complexity under the assessed conditions
- Privileges required None Attacker needs no account or login
- User interaction None No victim action needed
- Scope Unchanged Impact stays within the same security authority
- Confidentiality impact High Sensitive data can be exposed with serious impact
- Integrity impact High Protected data can be changed with serious impact
- Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Open in FIRST.org calculator