By vendor

Oracle vulnerabilities

Known CVEs affecting Oracle products, prioritized by severity, with SEC.co remediation and detection guidance.

135 published vulnerabilities · page 2 of 2

  • CVE-2026-46769HIGH 7.2

    Oracle's Application Development Framework (ADF), a middleware component used to build enterprise applications, contains a security vulnerability that allows administrators or other high-privileged users with network access to gain complete control over affected systems. An attacker with these elevated privileges can read, modify, or delete sensitive data and disrupt operations. The vulnerability affects two specific versions: 12.2.1.4.0 and 14.1.2.0.0.

  • CVE-2026-46867HIGH 7.2

    Oracle Enterprise Manager Base Platform contains a vulnerability in its Extensibility Framework that allows high-privileged attackers with network access to take over the system. The flaw affects versions 13.5 and 24.1, and exploitation requires HTTPS connectivity but does not need user interaction. A successful attack grants an attacker complete control over the Enterprise Manager platform, including ability to read, modify, or destroy data and disable services.

  • CVE-2026-46868HIGH 7.2

    A vulnerability exists in Oracle Enterprise Manager Base Platform that allows an authenticated administrator to gain complete control over the platform. The flaw is in the Extensibility Framework component and requires the attacker to already have high-privilege credentials and network access via HTTPS. Successful exploitation results in full compromise of the Enterprise Manager instance, affecting confidentiality, integrity, and availability. Versions 13.5 and 24.1 are affected.

  • CVE-2026-46922HIGH 7.2

    Oracle HR Intelligence, a component within Oracle E-Business Suite, contains a vulnerability that allows an authenticated high-privileged user with network access to take over the system. The vulnerability affects versions 12.2.3 through 12.2.15 and requires the attacker to already have elevated credentials, meaning it poses a risk primarily from internal threats or from attackers who have compromised privileged accounts. The impact is severe: an attacker could read, modify, or delete sensitive HR data and disrupt the entire HR Intelligence service.

  • CVE-2026-46938HIGH 7.2

    Oracle has published a high-severity vulnerability in its Cost Management module within E-Business Suite that allows privileged network attackers to fully compromise the system. The flaw affects versions 12.2.3 through 12.2.15 and requires the attacker to already possess high-level administrative credentials and network access. Successful exploitation grants complete control over the application's functionality, data, and availability.

  • CVE-2026-46953HIGH 7.2

    A vulnerability exists in Oracle's HRMS (UK) module within E-Business Suite that allows a privileged network attacker to fully compromise the system. The flaw affects payroll processing for UK organizations running versions 12.2.3 through 12.2.15. An attacker with high-level administrative credentials can exploit this over the network without user interaction, leading to complete takeover of the HRMS system including access to sensitive payroll, employee, and financial data.

  • CVE-2026-46956HIGH 7.2

    CVE-2026-46956 is a vulnerability in Oracle Property Manager, a module within Oracle E-Business Suite used for real estate and facility management operations. An attacker with high administrative privileges and network access can exploit this flaw to gain complete control over the Property Manager application, potentially compromising confidentiality, integrity, and availability of managed property data. The vulnerability stems from improper access controls in the Internal Operations component.

  • CVE-2026-46960HIGH 7.2

    A vulnerability in Oracle's Project Portfolio Analysis component (part of E-Business Suite) allows an attacker with elevated privileges and network access to take full control of the application. The flaw affects versions 12.2.3 through 12.2.15 and requires the attacker to already have high-level system access, but once leveraged, enables complete compromise including data theft, modification, and service disruption.

  • CVE-2026-46969HIGH 7.2

    CVE-2026-46969 is a high-severity vulnerability in Oracle Financials for EMEA (part of Oracle E-Business Suite) that allows a high-privileged attacker on your network to take full control of the system. The flaw affects versions 12.2.3 through 12.2.15 and can be exploited over HTTP without user interaction. An attacker with administrative or equivalent credentials could gain complete access to confidentiality, integrity, and availability of your financial data and systems.

  • CVE-2026-46970HIGH 7.2

    Oracle HR Intelligence, a component of Oracle E-Business Suite, contains a vulnerability that allows a privileged network attacker to take control of the system. The flaw affects supported versions 12.2.3 through 12.2.15 and requires the attacker to already have high-level administrative credentials to exploit it. Once exploited, an attacker could compromise confidentiality, integrity, and availability of HR data and system operations.

  • CVE-2026-46976HIGH 7.2

    Oracle Public Sector Payroll, a component of Oracle E-Business Suite, contains a vulnerability in its Internal Operations module that allows a high-privileged network attacker to gain complete control over the payroll system. Versions 12.2.3 through 12.2.15 are vulnerable. An attacker with administrative or elevated privileges who can reach the system over HTTP could compromise confidentiality, integrity, and availability—potentially disrupting payroll processing, modifying employee payment data, or exfiltrating sensitive compensation information.

  • CVE-2026-46914HIGH 7.1

    A flaw in Oracle Solaris 11.4's filesystem component allows an authenticated user on the local system to read sensitive data or crash the operating system. An attacker with standard user privileges can exploit this without needing to interact with the system graphically—it happens automatically through the vulnerable code path. The vulnerability is rated HIGH severity and poses a real risk to organizations running Solaris infrastructure, particularly those handling sensitive data or requiring high availability.

  • CVE-2026-46932HIGH 7.1

    A flaw in Oracle Enterprise Asset Management allows someone with low-level network access to view sensitive data or cause service disruptions. An authenticated user (even with minimal privileges) can send specially crafted HTTP requests to the application to either read confidential information or partially disable the service. The vulnerability affects versions 12.2.3 through 12.2.15 and does not require user interaction—an attacker simply needs valid login credentials and network connectivity to the system.

  • CVE-2026-35291MEDIUM 6.6

    Oracle WebLogic Server contains a vulnerability in its Console component that could allow a highly privileged attacker to take over the server if they have network access. The flaw affects versions 14.1.2.0.0 and 15.1.1.0.0 and requires the attacker to already have high-level administrative privileges and overcome additional technical barriers to exploit it. Successful exploitation would give an attacker complete control over the WebLogic Server's data and operations.

  • CVE-2026-35261MEDIUM 6.5

    Oracle Access Manager contains an authentication bypass vulnerability that allows attackers to gain unauthorized access to sensitive data without providing valid credentials. An attacker on a network can exploit this flaw through HTTP requests to read, modify, or delete data within the application. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.1.0, and requires no special privileges or user interaction to exploit.

  • CVE-2026-46810MEDIUM 6.5

    Oracle Identity Manager contains a flaw in its End User Self Service component that allows an attacker to modify, add, or delete certain data and read sensitive information without needing to log in first. The vulnerability affects two specific versions of the software and can be exploited remotely via network access through the IIOP protocol. No user interaction or special circumstances are required to trigger the attack.

  • CVE-2026-46869MEDIUM 6.5

    CVE-2026-46869 is a medium-severity vulnerability in Oracle MySQL Shell (versions 8.4.0–8.4.9 and 9.0.0–9.7.0) that allows an unauthenticated attacker on the network to access sensitive data stored within MySQL Shell. The attack requires a person to interact with a malicious input or link, but once triggered, an attacker can read confidential information without needing to authenticate. No integrity or availability impact occurs—this is purely a data exposure risk.

  • CVE-2026-46871MEDIUM 6.5

    MySQL Shell, Oracle's command-line interface and IDE extension for MySQL databases, contains a flaw that allows an authenticated attacker to read sensitive data without authorization. The vulnerability exists in the VS Code extension component and affects version 2026.2.0+9.6.1. An attacker who already has valid credentials can exploit this over the network to access confidential information stored within MySQL Shell's scope, but cannot modify or delete data.

  • CVE-2026-46979MEDIUM 6.5

    Oracle PeopleSoft Enterprise CS Campus Community version 9.2.38 contains a vulnerability in its integration and interfaces component that allows high-privileged attackers to access the system over HTTPS and read or modify sensitive institutional data. The vulnerability requires the attacker to already hold elevated administrative credentials, but once authenticated, they can view or alter critical campus and community information without additional obstacles. This represents a data confidentiality and integrity risk rather than a system availability threat.

  • CVE-2026-46770MEDIUM 6.1

    Oracle Application Development Framework (ADF), a core component of Oracle Fusion Middleware, contains a security flaw that allows an attacker to access or modify sensitive data without authentication. The vulnerability affects versions 12.2.1.4.0 and 14.1.2.0.0. An attacker needs only network access and must trick a legitimate user into taking an action—such as clicking a malicious link—to trigger the vulnerability. Once successful, the attacker gains the ability to read or alter data within the ADF application, potentially affecting downstream systems that rely on it. This is not currently a known or active exploit in the wild, but it warrants prompt attention given the data-access implications.

  • CVE-2026-46812MEDIUM 6.1

    Oracle Access Manager versions 12.2.1.4.0 and 14.1.2.1.0 contain an authentication flaw that allows an unauthenticated network attacker to read or modify data within the application. The vulnerability requires a user to interact with a malicious request, but successful exploitation can affect not only Access Manager itself but potentially other connected systems. This is a medium-severity issue with network-accessible attack vectors and no special privileges required for initial access.

  • CVE-2026-46768MEDIUM 6.0

    A denial-of-service vulnerability exists in Oracle VM VirtualBox 7.2.8 that allows a high-privileged user with local access to crash or hang the hypervisor. The issue resides in the VMSVGA device component and requires administrator-level credentials to trigger, but when exploited, can render the virtualization platform unavailable and potentially affect guest virtual machines. The vulnerability does not compromise data confidentiality or integrity—it is purely an availability threat.

  • CVE-2026-46825MEDIUM 6.0

    CVE-2026-46825 is a medium-severity vulnerability in Oracle VM VirtualBox 7.2.8 affecting the VMSVGA device driver. A user with high system privileges can modify or delete critical data within VirtualBox or data accessible through it. The vulnerability requires local access and elevated privileges to exploit, but can impact not only VirtualBox itself but also systems and data it manages. Oracle has classified this as a scope-change issue, meaning an attacker could potentially affect resources beyond VirtualBox's immediate boundary.

  • CVE-2026-46877MEDIUM 6.0

    A vulnerability in Oracle VM VirtualBox version 7.2.8 allows an administrator or highly privileged user on the host system to read sensitive data from the virtual machine. The flaw is in the VMSVGA graphics device component. An attacker would need administrative-level access to the infrastructure running VirtualBox, but from that position can extract confidential information that VirtualBox can access. The vulnerability does not enable attackers to modify or delete data, nor does it crash the system.

  • CVE-2026-46790MEDIUM 5.3

    Oracle WebCenter Content version 14.1.2.0.0 contains an information disclosure vulnerability that allows an unauthenticated attacker to read sensitive data over the network without requiring credentials or user interaction. The vulnerability is exposed through HTTP and rated medium severity due to its limited scope—only confidentiality is affected, with no impact to data integrity or system availability.

  • CVE-2026-46830MEDIUM 5.3

    Oracle REST Data Services contains an information disclosure vulnerability in its Mongoapi component that allows an unauthenticated attacker to read sensitive data over the network without authentication. An attacker with network access can exploit this flaw via HTTPS to gain unauthorized visibility into data normally protected by REST Data Services, though they cannot modify or delete information. The vulnerability affects versions 24.2.0 through 26.1.0 and requires no special conditions—it's straightforward to trigger.

  • CVE-2026-46841MEDIUM 5.3

    Oracle REST Data Services versions 24.2.0 through 26.1.0 contain a network-accessible vulnerability that allows unauthenticated attackers to read sensitive data. An attacker on the network can reach the service over HTTPS without credentials and gain unauthorized access to a subset of the data REST Data Services manages. This is not a critical vulnerability—it does not enable system takeover, data modification, or service disruption—but it does represent a meaningful confidentiality risk for organizations relying on REST Data Services for data access control.

  • CVE-2026-46842MEDIUM 5.3

    Oracle REST Data Services versions 24.2.0 through 26.1.0 contain a vulnerability that allows an unauthenticated attacker to modify, add, or delete data accessible through the service over the network. The vulnerability requires no special conditions to exploit and can be triggered via standard HTTPS connections. While an attacker cannot read data or crash the service, they can alter stored information, which poses a direct integrity risk to applications relying on ORDS for data access.

  • CVE-2026-46843MEDIUM 5.3

    Oracle REST Data Services versions 24.2.0 through 26.1.0 contain a vulnerability that allows an attacker without credentials to trigger a partial denial of service over the network via HTTPS. The vulnerability is in the Core component and requires no special user interaction. An attacker can exploit this remotely to degrade availability of the REST Data Services instance, though data confidentiality and integrity are not at risk.

  • CVE-2026-46772MEDIUM 4.7

    Oracle's Application Development Framework (ADF), a core component of Fusion Middleware, contains a privilege-escalation vulnerability affecting versions 12.2.1.4.0 and 14.1.2.0.0. An attacker with high-level administrative access and direct infrastructure access could exploit insufficient privilege controls to read sensitive application data or modify certain records. The attack is not trivial—it requires both elevated credentials and specific configuration conditions—but poses meaningful risk to organizations running vulnerable ADF instances, particularly those handling sensitive business data through ADF-based applications.

  • CVE-2026-46771MEDIUM 4.1

    CVE-2026-46771 is a localized privilege-escalation vulnerability in Oracle Application Development Framework (ADF) that allows a highly privileged attacker already logged into the infrastructure to access sensitive application data. The attacker must be an administrative user on the machine running ADF, and even then exploiting it requires specific conditions to be met. The primary risk is unauthorized disclosure of data within ADF systems—the vulnerability does not enable attackers to modify or delete data, nor does it allow takeover of the ADF service itself.

  • CVE-2026-46815LOW 3.2

    CVE-2026-46815 is a low-severity information disclosure flaw in Oracle VM VirtualBox 7.2.8 affecting the VMSVGA graphics device driver. A high-privilege user already logged into a system running VirtualBox can read a limited subset of VirtualBox data that should not be accessible to them. The vulnerability does not enable attackers to modify data, crash the application, or gain system-level control. Its scope extends beyond VirtualBox itself—successful exploitation could indirectly expose data relevant to other products running on or managed by the affected host.

  • CVE-2026-46816LOW 3.2

    CVE-2026-46816 is a low-severity information disclosure vulnerability affecting Oracle VM VirtualBox 7.2.8. A high-privileged user already logged into the host system running VirtualBox can read a limited subset of data accessible to VirtualBox. The attack requires existing local access with administrative-level privileges and occurs through the VMSVGA device component. Because VirtualBox often runs on infrastructure managing multiple virtual machines, successful exploitation could expose sensitive data across guest systems, though the scope of readable data is restricted.

  • CVE-2026-46874LOW 3.2

    Oracle VM VirtualBox version 7.2.8 contains a privilege escalation vulnerability affecting the Core component. An attacker with high-level privileges and local access to the system running VirtualBox can read sensitive data that VirtualBox manages or processes. While the vulnerability itself resides in VirtualBox, successful exploitation could expose information relevant to other systems or virtual machines it hosts, expanding the security footprint beyond VirtualBox alone. The vulnerability requires the attacker to already have administrative or high-privilege access to the infrastructure, which significantly limits the practical attack surface in most environments.

  • CVE-2026-46977LOW 3.2

    A vulnerability in Oracle VM VirtualBox's VMSVGA device component could allow a high-privileged user already logged into the host system to read a limited subset of sensitive data stored within VirtualBox. Version 7.2.8 is affected. The issue is classified as low-severity because successful exploitation requires administrative-level access to the infrastructure where VirtualBox runs, and the data exposure is partial rather than complete. The scope impacts extend beyond VirtualBox itself, meaning the unauthorized read could potentially affect other systems or data managed through the hypervisor.