HIGH 7.2

CVE-2026-46938: Oracle Cost Management Remote Compromise (CVSS 7.2)

Oracle has published a high-severity vulnerability in its Cost Management module within E-Business Suite that allows privileged network attackers to fully compromise the system. The flaw affects versions 12.2.3 through 12.2.15 and requires the attacker to already possess high-level administrative credentials and network access. Successful exploitation grants complete control over the application's functionality, data, and availability.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-284
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-18

NVD description (verbatim)

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-46938 is an improper access control vulnerability (CWE-284) in the Oracle Cost Management Cost Planning component. It requires high privilege credentials and network access via HTTP but no user interaction. The vulnerability results in unrestricted confidentiality, integrity, and availability impact within the affected component's scope. The CVSS 3.1 Base Score of 7.2 reflects the combination of high-privilege requirement (which limits exposure) and complete system compromise capability once that privilege threshold is met.

Business impact

Compromise of Oracle Cost Management directly impacts financial planning, cost allocation, and resource budgeting operations. Attackers gaining control can manipulate cost data, alter planning assumptions, extract sensitive financial information, or disrupt budget forecasting processes. Organizations relying on this system for procurement decisions and cost visibility face potential for fraudulent data manipulation and decision-making based on corrupted financial intelligence.

Affected systems

Oracle E-Business Suite Cost Management versions 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, and 12.2.15 are affected. Organizations running Cost Planning functionality within this version range should immediately assess their environment. The vulnerability does not affect earlier or later versions outside the 12.2.3–12.2.15 range.

Exploitability

Exploitation requires the attacker to already hold high-privilege (administrative-level) credentials within the organization and have network connectivity to the Cost Management HTTP interface. While the vulnerability itself is easily exploitable once these prerequisites are met, the high-privilege requirement significantly limits the attack surface to insider threats or compromised administrative accounts. Public exploit code is not referenced in the vulnerability record.

Remediation

Apply vendor-provided security patches for Oracle Cost Management immediately. Consult the Oracle Critical Patch Update (CPU) advisory for June 2026 for exact patch versions applicable to your E-Business Suite release. Organizations unable to patch within acceptable timeframes should implement strict network access controls limiting HTTP connections to Cost Management to only authorized administrative users and systems, and enable enhanced logging on cost data modifications.

Patch guidance

Verify the applicable patch version for your specific E-Business Suite release level (12.2.3–12.2.15) in the Oracle June 2026 CPU advisory. Oracle typically provides patches through their support portal; plan patching during a scheduled maintenance window as E-Business Suite updates may require application downtime. Test patches in a non-production environment first, particularly given Cost Management's role in financial reporting. Establish a clear rollback plan. Organizations on extended support should confirm patch availability for their release before scheduling maintenance.

Detection guidance

Monitor HTTP request logs for unusual administrative access patterns to Cost Management modules, particularly from unexpected source IPs or during non-business hours. Enable Cost Planning application logging to capture data modification events and access attempts. Review database audit trails for changes to cost data, cost structures, or planning assumptions by administrative accounts. Baseline normal administrator behavior first to identify anomalies. Look for repeated failed authentication attempts followed by successful administrative logins, which may indicate credential compromise.

Why prioritize this

While the CVSS score of 7.2 is high, the requirement for pre-existing high-privilege credentials limits immediate external risk. However, this should be deprioritized only if you have strong confidence in your administrative account security posture and no indicators of compromise. Organizations with mixed security maturity, legacy access controls, or shared administrative accounts should treat this as critical. The financial data at stake in Cost Management makes insider threat vectors particularly damaging, elevating practical risk beyond the CVSS score.

Risk score, explained

The 7.2 CVSS score reflects the severe impact (complete confidentiality, integrity, and availability compromise) balanced against the high-privilege requirement that restricts attack surface. The CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H vector indicates network accessibility, low attack complexity, high privileges needed, no user interaction required, and unrestricted impact scope. The score should be considered a floor for risk assessment; organizations should apply local context (e.g., user privileged account hygiene, network segmentation, audit logging quality) to derive an organization-specific risk rating.

Frequently asked questions

Do I need to patch if I'm not actively using Cost Planning functionality?

Yes. Even unused modules within E-Business Suite remain accessible and vulnerable unless formally disabled or deactivated. An attacker with administrative access could enable and exploit dormant functionality. Patching is the proper remediation regardless of current usage patterns.

Can an external attacker exploit this without already having high-privilege credentials?

No. The vulnerability explicitly requires high-privilege (administrative-level) credentials to be exploited. External attackers would first need to compromise such an account through separate attack vectors like phishing or credential theft. However, you should assume that if you have indicators of compromise affecting administrative accounts, this vulnerability becomes immediately exploitable.

What's the difference between this and a zero-day?

This is a known vulnerability disclosed through Oracle's official channel. It is not a zero-day. Organizations have the advantage of vendor guidance, patch availability, and a disclosed CVE for tracking. Exploit code is not publicly available, but defenders should still prioritize patching.

If we've isolated Cost Management on an internal network, is our risk lower?

Yes, significantly. Network isolation reduces the attack surface by limiting who can reach the HTTP interface. However, this does not eliminate risk from insider threats or compromised administrative accounts on that network. Network controls should be layered with strong access controls, credential management, and audit logging.

This analysis is based on the official CVE record published on 2026-06-17 and modified 2026-06-18. Patch version numbers, availability, and specific remediation steps must be verified against Oracle's official Critical Patch Update advisory and vendor documentation. SEC.co makes no guarantee of patch effectiveness or completeness for specific configurations. Organizations should conduct their own risk assessment based on local threat models, asset criticality, and compliance requirements. This document does not constitute professional security advice and should be reviewed by qualified security personnel before implementation. Source: NVD (public-domain), retrieved 2026-07-25. Analysis generated by SEC.co (claude-haiku-4-5).