Skip to main content
Change Risk Intel

CVE-2026-46817 — Oracle E-Business Suite Improper Privilege Management Vulnerability

Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments.

CVSS
9.8 (Critical)
KEV status
CISA KEV — Listed
First seen (CISA KEV)
Recommended change window
Emergency change — coordinate with Finance to schedule Oracle Payments downtime the same weekend; roll back readiness is mandatory.
Affected products
Oracle E-Business Suite

Why this one matters to a CAB

Oracle E-Business Suite’s Payments module handles bank routing numbers, ACH batches, and card processor tokens. An unauthenticated takeover of Oracle Payments is a Sarbanes-Oxley scoping event before it is a security event — audit will want a written narrative of when the vulnerability was disclosed, when it was patched, and whether any financial transaction is in scope for restatement risk.

Defender’s angle

  • Immediate boundary: put the EBS iAS HTTP tier behind a WAF rule that denies any request to /OA_HTML/OaCommon from outside the corporate egress IP range. This is not a fix, it is a containment step for the interval between disclosure and patch.
  • Detection: enable the EBS “Payments Manager Audit” trail before the patch window. Any unexpected IBY_PAYMENT_METHODS_VL update between the disclosure date and the patch date is investigation-worthy.
  • Backup posture: take a cold RMAN backup of the IBY schema before the patch runs. Oracle’s April CPU historically has had patching regressions in the payments code path.

What to bring to CAB

A joint change record signed by the Oracle EBS DBA lead, the Controllership team, and the Information Security lead. Include the Oracle Payments patch bundle number from Oracle Support and the rollback plan (usually opatch rollback plus recompile).

Sources

This page summarizes publicly available information from CISA KEV, NVD, and the listed vendor advisory. Change Risk Intel does not publish exploit walkthroughs. Verify with your vendor before scheduling any change window.