HIGH 8.5

CVE-2026-46915: Oracle E-Business Suite CMRO Privilege Escalation Vulnerability

Oracle's Complex Maintenance, Repair and Overhaul (CMRO) component within E-Business Suite contains a privilege escalation vulnerability that allows attackers with low-level network access to compromise the system. An attacker would need valid credentials or low privileges to initiate an attack via HTTP, but exploitation is complex and not trivial. If successful, the attacker could gain complete control over CMRO and potentially affect other connected Oracle systems due to the scope change.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.5 HIGH · CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses (CWE)
CWE-284
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-18

NVD description (verbatim)

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

This vulnerability in Oracle Complex Maintenance, Repair and Overhaul (versions 12.2.3 through 12.2.15) stems from improper access controls (CWE-284: Improper Access Control), allowing a low-privileged network attacker to escalate privileges via HTTP without user interaction. The high CVSS 3.1 score of 8.5 reflects the attack's network accessibility combined with changed scope—while the vulnerability exists within CMRO itself, successful exploitation can impact confidentiality, integrity, and availability across Oracle E-Business Suite and potentially interconnected systems. The high complexity (AC:H) suggests specific conditions or knowledge are required for successful exploitation.

Business impact

Compromise of CMRO could disrupt critical maintenance and repair operations that many organizations depend on for asset management and operational continuity. The scope change designation means that secondary systems connected to E-Business Suite—including supply chain, procurement, or asset tracking components—could also be affected. Organizations using CMRO for regulatory compliance or safety-critical maintenance records face reputational and legal exposure if data integrity is compromised.

Affected systems

Oracle E-Business Suite versions 12.2.3 through 12.2.15 running the Complex Maintenance, Repair and Overhaul component are directly affected. Secondary systems within the same E-Business Suite instance or those integrated with CMRO may be indirectly compromised due to scope change. Customers should verify their exact CMRO version and any downstream dependencies on this module.

Exploitability

Exploitation requires network access and valid low-level credentials—meaning an attacker cannot exploit this as an anonymous user. The high complexity factor suggests specific application state, configuration, or knowledge barriers exist that prevent trivial exploitation. However, for attackers with insider knowledge, low user privileges, or ability to compromise a low-privileged account, this vulnerability presents a viable path to system takeover. The absence from the CISA Known Exploited Vulnerabilities catalog as of the knowledge cutoff does not guarantee lack of active exploitation in the wild.

Remediation

Apply the latest security patches released by Oracle for E-Business Suite CMRO. Verify the patched version against Oracle's official security advisory and test thoroughly in a non-production environment before deployment. Implement network segmentation to restrict HTTP access to CMRO from untrusted sources, and enforce strong authentication and role-based access controls to minimize the number of low-privileged users who can reach the vulnerable component. Monitor for suspicious privilege escalation attempts.

Patch guidance

Consult Oracle's official security advisory for CVE-2026-46915 to identify the specific patched version for your current CMRO build. The vulnerability spans versions 12.2.3–12.2.15, so any release outside that range or a security patch for your branch should be evaluated. Apply patches during scheduled maintenance windows and validate system functionality against your maintenance workflows post-patching. Oracle typically bundles E-Business Suite patches; ensure you do not inadvertently roll back security fixes when applying other updates.

Detection guidance

Monitor for HTTP requests to CMRO endpoints that attempt to modify data or access resources inconsistent with the requester's role or job function. Log and alert on failed access attempts followed by successful authentication using low-privileged accounts. Review access logs for unusual patterns such as privilege escalation events or unexpected modification of maintenance records, asset data, or system configurations within CMRO. Enable detailed audit logging if available and correlate events across E-Business Suite to detect lateral movement after initial CMRO compromise.

Why prioritize this

This vulnerability warrants prompt attention due to its HIGH CVSS score (8.5), full confidentiality/integrity/availability impact, and scope change affecting downstream systems. Although exploitation requires low-level privileges and non-trivial conditions (AC:H), organizations where CMRO is business-critical should prioritize patching. The longer a vulnerable version runs in production, the greater the window for insider threats or compromised low-privilege accounts to escalate. The lack of KEV status does not reduce urgency; it may reflect the recency of disclosure or low prevalence of active exploitation reporting.

Risk score, explained

The CVSS 3.1 Base Score of 8.5 (HIGH) reflects: (1) network accessibility (AV:N) enabling remote attack; (2) low privilege barrier (PR:L) requiring valid but minimal credentials; (3) high attack complexity (AC:H) that limits widespread automated exploitation; (4) scope change (S:C) meaning impacts extend to systems beyond CMRO; (5) high impact across all three security dimensions—confidentiality, integrity, and availability. The score balances the relative difficulty of exploitation against the severity of potential harm and broad scope.

Frequently asked questions

What privileges does an attacker need to exploit this vulnerability?

An attacker must possess low-level credentials—typically a standard user account with minimal permissions—and network access to CMRO via HTTP. This means external threats require either a valid user account (compromised or legitimate) or ability to obtain low-level credentials. Insider threats with baseline access pose the greatest risk.

Does this vulnerability affect older versions of E-Business Suite outside the 12.2.3–12.2.15 range?

Only E-Business Suite versions 12.2.3 through 12.2.15 running CMRO are documented as affected. If you operate a different major version branch, consult Oracle's advisory to confirm your build is out of scope, but do not assume it is unaffected without explicit vendor confirmation.

What does 'scope change' mean for my risk assessment?

Scope change (S:C in the CVSS vector) indicates that a successful attack on CMRO could compromise confidentiality, integrity, or availability of resources outside CMRO itself—such as other E-Business Suite modules, linked systems, or shared databases. This elevates the blast radius and means patching CMRO protects more than just maintenance data.

Is there public exploit code available for this vulnerability?

As of the disclosure date (June 2026), this vulnerability does not appear on the CISA Known Exploited Vulnerabilities list. However, the absence of public tooling does not guarantee safety; conduct your own threat modeling based on whether you have high-value low-privileged accounts or insider risk factors.

This analysis is based on the CVE record and vendor advisory as of the publication date. SEC.co does not conduct independent exploit testing or provide guaranteed patch version numbers; always verify specific remediation steps against Oracle's official security advisory for your environment. CVSS scores are provided by the vendor and reflect base conditions; your environmental risk may differ significantly. This intelligence is intended to inform security decision-making and should be combined with your own threat modeling, asset inventory, and business criticality assessment. Source: NVD (public-domain), retrieved 2026-07-25. Analysis generated by SEC.co (claude-haiku-4-5).