CVE-2026-46956: Oracle Property Manager Privilege Escalation Vulnerability (CVSS 7.2)
CVE-2026-46956 is a vulnerability in Oracle Property Manager, a module within Oracle E-Business Suite used for real estate and facility management operations. An attacker with high administrative privileges and network access can exploit this flaw to gain complete control over the Property Manager application, potentially compromising confidentiality, integrity, and availability of managed property data. The vulnerability stems from improper access controls in the Internal Operations component.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-284
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-18
NVD description (verbatim)
Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in takeover of Oracle Property Manager. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
This vulnerability exists in Oracle Property Manager versions 12.2.3 through 12.2.15 and is classified under CWE-284 (Improper Access Control). The attack requires HTTP network access and high privilege credentials, but no user interaction is required. The flaw allows authenticated administrative users to bypass intended access restrictions and achieve full system compromise. CVSS 3.1 score of 7.2 reflects the severity: while exploitation demands elevated privileges, successful attacks result in complete confidentiality, integrity, and availability impacts across the affected component.
Business impact
Compromise of Oracle Property Manager can expose sensitive property management data, including lease agreements, tenant information, facility inventories, and financial records. An attacker could alter maintenance schedules, redirect service vendor payments, modify lease terms, or deny access to facility management functions. For organizations using Property Manager for critical real estate operations, this creates operational disruption risk, regulatory compliance exposure (particularly if tenant or financial data is altered), and potential reputational harm if property operations are visibly degraded.
Affected systems
Oracle Property Manager in E-Business Suite versions 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, and 12.2.15 are vulnerable. Organizations running Oracle EBS must verify whether Property Manager is deployed and which versions are in use. This vulnerability does not affect earlier 12.2 versions (pre-12.2.3) or later versions beyond 12.2.15.
Exploitability
Exploitation requires high-privilege (administrative) credentials and network access to the HTTP interface hosting Property Manager. The vulnerability is 'easily exploitable' given those preconditions—no complex manipulation or user interaction is needed once authenticated access is established. However, the prerequisite of high privileges significantly limits the attacker pool to insiders, compromised admin accounts, or attackers who have already breached initial access controls. The risk is highest in environments with weak credential hygiene or excessive privilege delegation.
Remediation
Verify your Oracle EBS deployment includes Property Manager and confirm the specific version. Contact Oracle Support or consult the Oracle Critical Patch Update (CPU) schedule for available patches. Patches are released as part of quarterly CPU bundles; apply the patch appropriate to your version, which will be documented in the Oracle security bulletin published alongside the CVE. If patching is delayed, implement strict access controls limiting administrative access to Property Manager to named, audited personnel, and enable detailed logging of all administrative actions.
Patch guidance
Oracle addresses this vulnerability through its quarterly Critical Patch Update (CPU) process. Verify the exact patch version applicable to your Property Manager version (12.2.3–12.2.15) in the official Oracle security advisory. Test patches in a non-production environment before deployment to ensure compatibility with custom extensions and dependent modules. Patching should be coordinated with your EBS maintenance windows to minimize disruption. Document the patch level and deployment date for audit purposes.
Detection guidance
Monitor HTTP traffic to Property Manager endpoints for administrative users performing unusual operations, particularly those modifying access controls, financial records, or system configurations. Enable and review detailed Property Manager audit logs focusing on privilege escalation events and bulk data modification operations. Use your SIEM to correlate admin logins to Property Manager with subsequent abnormal application behavior. Network-based detection should flag suspicious authentication patterns or administrative activity from unexpected source IPs. Consider baseline-building for normal admin activity to improve anomaly detection.
Why prioritize this
Although this vulnerability requires high-privilege credentials, it warrants urgent attention because successful exploitation grants complete application takeover. Organizations with weaker identity governance, shared admin accounts, or elevated privilege access risks should prioritize remediation. The data exposure potential (property, lease, and financial records) adds compliance implications. Prioritize patching if your environment has experienced any identity compromise, if admin passwords are infrequently rotated, or if Property Manager manages mission-critical real estate operations.
Risk score, explained
CVSS 3.1 score of 7.2 (HIGH) reflects the complete confidentiality, integrity, and availability impact possible after exploitation, combined with low attack complexity and no user interaction requirement. The score is tempered by the requirement for high-privilege credentials—a significant limiting factor. Organizations with robust privilege access management and strong identity controls will face lower practical risk; those with permissive admin access face substantially higher risk and should treat this as critical.
Frequently asked questions
Do I need to patch immediately if I run Oracle Property Manager?
Prioritize patching if you manage critical real estate operations, have experienced recent credential compromises, or lack robust administrative access controls. If admin credentials are tightly scoped and regularly audited, you have some flexibility to coordinate patching with scheduled maintenance windows. However, do not delay indefinitely—create a specific remediation timeline within your next monthly cycle.
Does this vulnerability affect non-Property Manager Oracle EBS modules?
No. CVE-2026-46956 is specific to the Property Manager component within E-Business Suite. Other EBS modules (AR, AP, GL, HR, etc.) are not affected. However, verify with Oracle that your specific version range matches the affected versions listed (12.2.3–12.2.15).
Can this be exploited by unauthenticated attackers?
No. The vulnerability requires high-privilege administrative credentials and network access to Property Manager. An unauthenticated attacker cannot exploit this flaw directly. Risk is highest from compromised admin accounts, disgruntled insiders, or attackers who have established persistence with elevated access through other means.
What should I do if I cannot patch immediately?
Implement compensating controls: restrict administrative console access via firewall rules to trusted internal networks, require multi-factor authentication for all admin logins, enforce privileged session isolation (PAM), and enable comprehensive audit logging. Monitor these logs continuously. These measures reduce risk but do not eliminate it—patching remains essential.
This analysis is based on the published CVE description and official CVSS metrics. Verify all patch version numbers and availability against the official Oracle security advisory before deployment. SEC.co does not provide specific patch recommendations or guarantee the completeness of this assessment for your specific configuration. Consult with Oracle Support and your internal security team regarding the business criticality and remediation timeline for your environment. This vulnerability is not currently listed on the CISA KEV catalog as of the published date, but status may change. Source: NVD (public-domain), retrieved 2026-07-26. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35262HIGHOracle Data Integrator Authentication Bypass – Data Exposure Risk
- CVE-2026-35269HIGHOracle Identity Manager REST WebServices Authentication Bypass
- CVE-2026-35271HIGHOracle PeopleSoft WebLogic Unauthenticated Data Access Vulnerability (CVSS 8.7)
- CVE-2026-35275HIGHOracle VM VirtualBox Shared Folders Privilege Escalation Vulnerability (CVSS 7.5)
- CVE-2026-35277HIGHOracle REST Data Services Authorization Bypass
- CVE-2026-35311HIGHOracle WebLogic Server Remote Takeover via Low-Privilege Access Control Flaw
- CVE-2026-35314HIGHOracle Access Manager Authentication Bypass (CVSS 7.3)
- CVE-2026-35315HIGHOracle WebCenter Content Remote Takeover via Low-Privilege HTTP Access