HIGH 8.8

CVE-2026-46929: Oracle Cost Management Access Control Vulnerability (CVSS 8.8)

CVE-2026-46929 is a high-severity vulnerability in Oracle's Cost Management component within Oracle E-Business Suite (versions 12.2.3 through 12.2.15). An attacker with a low-level user account and network access can exploit this flaw via HTTP to gain complete control over the Cost Management system. The vulnerability requires no user interaction, making it straightforward to exploit. Successful exploitation allows attackers to read sensitive data, modify cost planning information, and disrupt system availability.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-269, CWE-284, CWE-287, CWE-306
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-18

NVD description (verbatim)

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

The vulnerability stems from improper access control mechanisms in the Cost Planning component (CWE-269: Improper Access Control; CWE-284: Improper Access Control; CWE-287: Improper Authentication; CWE-306: Missing Authentication for Critical Function). A low-privileged network user can leverage HTTP connectivity to bypass authorization checks and achieve unauthenticated or elevated-privilege actions within Cost Management. The attack requires minimal complexity and no user interaction, as reflected in the CVSS 3.1 vector (AV:N/AC:L/PR:L/UI:N). The flaw results in complete confidentiality, integrity, and availability compromise of the affected component.

Business impact

Complete takeover of Cost Management exposes your organization to several risks: attackers can exfiltrate sensitive cost data (confidentiality impact), modify cost allocations, budgets, and planning information (integrity impact), and disable the cost planning function entirely (availability impact). In manufacturing, distribution, or complex enterprise environments, Cost Management disruption can halt financial reporting, distort operational cost visibility, and compromise audit trails. Data theft could enable competitive intelligence gathering or regulatory disclosure incidents. The broad scope of potential damage—spanning finance, compliance, and operations—makes this a material business risk.

Affected systems

Oracle E-Business Suite Cost Management module, versions 12.2.3 through 12.2.15, is affected. This spans a significant release window. Organizations running Cost Management in these versions on-premises or in hosted/cloud deployments are in scope. The vulnerability does not affect later versions (verify your installed version against Oracle's advisory); patching or upgrading is required for affected versions.

Exploitability

This vulnerability is easily exploitable. An attacker needs only a valid low-privilege user account (such as a standard cost analyst or read-only user) and network access to the Cost Management HTTP interface. No special tools, code execution, or user interaction are required. The simplicity of exploitation—combined with the broad window of affected versions and the high-value targets typically using Oracle EBS—creates significant real-world risk. Organizations should treat this as highly exploitable in their environment if the affected version range is present.

Remediation

Patch your Oracle Cost Management installations to a version outside the 12.2.3–12.2.15 range. Consult the Oracle Critical Patch Update (CPU) release notes published around the vulnerability disclosure date (June 2026) for the specific patch version applicable to your version. If immediate patching is not possible, implement compensating controls: restrict network access to Cost Management HTTP endpoints to known administrative and trusted user IP ranges, apply principle of least privilege to user account permissions, and monitor for suspicious Cost Management API or HTTP activity. Verify patching effectiveness by confirming the installed version post-update.

Patch guidance

Obtain the applicable security patch from Oracle's official patch delivery mechanism (Oracle Support Portal, My Oracle Support). The patch will address the access control flaws identified in the vulnerability. Before deploying to production, test the patch in a non-production environment to confirm compatibility with your Cost Management configuration and dependent processes. Plan a maintenance window that minimizes disruption to financial reporting cycles. After patching, validate that Cost Management functionality remains intact and that legitimate user access is unaffected.

Detection guidance

Monitor Cost Management HTTP traffic for unusual patterns: requests from unexpected IP addresses, high volumes of enumeration or reconnaissance requests, and API calls that exceed normal usage patterns for low-privileged users. Check Cost Management audit logs for unauthorized modifications to cost master data, budget allocations, or cost planning parameters. Look for successful login events from low-privilege accounts followed by administrative or cross-user data access. Implement network-based detection rules for suspicious HTTP requests targeting Cost Management endpoints. A SIEM integration can correlate Cost Management logs with network IDS alerts to identify exploitation attempts in real time.

Why prioritize this

This vulnerability merits urgent patching priority due to the combination of high CVSS score (8.8), easy exploitability, broad affected version range, and material business impact. Cost Management controls sensitive financial data and processes; compromise directly threatens confidentiality and integrity of financial reporting. The low barrier to exploitation (valid low-privilege account only) increases likelihood of exploitation in real-world environments. Organizations should prioritize patching this vulnerability within their standard critical vulnerability response SLA (typically 1–2 weeks).

Risk score, explained

The CVSS 3.1 score of 8.8 (HIGH severity) reflects the maximum impact scope: an attacker with low privilege can gain full confidentiality, integrity, and availability impact across Cost Management. The score appropriately weights the easily exploitable attack vector (network-accessible HTTP interface, low complexity, low privilege required, no user interaction). While the scope remains unchanged (impact is limited to the Cost Management component itself, not the entire E-Business Suite), the breadth of impact within that scope and the ease of exploitation justify the high score. This is not a critical 9.0+ vulnerability only because exploitation requires a valid user account; however, it approaches that threshold in severity.

Frequently asked questions

Do we need to patch all versions between 12.2.3 and 12.2.15, or only specific ones?

All versions in the range 12.2.3 through 12.2.15 are affected. Patch immediately if your installed version falls within that range. Check your version with `select release_name from fnd_product_groups where product_code = 'MFGCOM'` in your Oracle database, or review your system's configuration details. Any version outside this range (e.g., 12.2.2 or 12.2.16+) is not affected, but verify against Oracle's official advisory to be certain.

Can we mitigate this without patching?

Network segmentation is the most effective interim control: restrict HTTP access to Cost Management to a whitelist of trusted IPs (administrative networks, specific business units). Enforce principle of least privilege by auditing user permissions and removing unnecessary access. Monitor all Cost Management activity closely. However, these controls do not eliminate the vulnerability itself; they reduce the attack surface. Patching remains the required remediation. Plan to patch as soon as possible, even if interim controls are in place.

Does this vulnerability affect Oracle Cloud Applications (SaaS)?

This vulnerability is specific to Oracle E-Business Suite (EBS), which is an on-premises or hosted deployment model. If your organization uses Oracle Cloud ERP (cloud-native SaaS), you are not affected. If you use EBS deployed on Oracle Cloud Infrastructure (OCI) or other cloud providers, you are affected and must apply the patch. Confirm your deployment model with your Oracle administrator or consulting partner.

How do we verify that the patch was applied successfully?

After patching, confirm the version of Cost Management by querying the database (see FAQ item 1) or reviewing the patch installation log. Oracle patch installation logs are typically located in `$ORACLE_HOME/cfgtoollogs/`. Validate that Cost Management functionality works correctly by executing a test transaction (e.g., creating a test cost allocation or viewing cost data). Run a network-based vulnerability scanner against the Cost Management interface to confirm the vulnerability is no longer detectable. Document the patch date, version, and testing results for compliance and audit purposes.

This analysis is based on publicly available vulnerability information and Oracle's disclosure. Specific patch version numbers, availability dates, and deployment instructions should be verified against Oracle's official Critical Patch Update advisories and your Oracle support contract. Organizations should test patches in non-production environments before deploying to production. This content is for informational purposes and should not be construed as legal, compliance, or technical advice. Consult your Oracle support team or a qualified security consultant for guidance tailored to your specific environment and risk posture. Source: NVD (public-domain), retrieved 2026-07-25. Analysis generated by SEC.co (claude-haiku-4-5).