CVE-2026-46817 — Oracle E-Business Suite Improper Privilege Management Vulnerability
Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.
- CVSS
- 9.8 (Critical)
- KEV status
- CISA KEV — Listed
- First seen (CISA KEV)
- Recommended change window
- Emergency change — coordinate with Finance to schedule Oracle Payments downtime the same weekend; roll back readiness is mandatory.
- Vendor advisory
- https://www.oracle.com/security-alerts/cspumay2026.html
- Affected products
- Oracle E-Business Suite
Why this one matters to a CAB
Oracle E-Business Suite’s Payments module handles bank routing numbers, ACH batches, and card processor tokens. An unauthenticated takeover of Oracle Payments is a Sarbanes-Oxley scoping event before it is a security event — audit will want a written narrative of when the vulnerability was disclosed, when it was patched, and whether any financial transaction is in scope for restatement risk.
Defender’s angle
- Immediate boundary: put the EBS
iASHTTP tier behind a WAF rule that denies any request to/OA_HTML/OaCommonfrom outside the corporate egress IP range. This is not a fix, it is a containment step for the interval between disclosure and patch. - Detection: enable the EBS “Payments Manager Audit” trail
before the patch window. Any unexpected
IBY_PAYMENT_METHODS_VLupdate between the disclosure date and the patch date is investigation-worthy. - Backup posture: take a cold RMAN backup of the
IBYschema before the patch runs. Oracle’s April CPU historically has had patching regressions in the payments code path.
What to bring to CAB
A joint change record signed by the Oracle EBS DBA lead, the Controllership team, and the Information Security lead. Include the Oracle Payments patch bundle number from Oracle Support and the rollback plan (usually opatch rollback plus recompile).
Sources
This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.