CVE-2026-46960: Oracle Project Portfolio Analysis Privilege Escalation Vulnerability
A vulnerability in Oracle's Project Portfolio Analysis component (part of E-Business Suite) allows an attacker with elevated privileges and network access to take full control of the application. The flaw affects versions 12.2.3 through 12.2.15 and requires the attacker to already have high-level system access, but once leveraged, enables complete compromise including data theft, modification, and service disruption.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-284
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-18
NVD description (verbatim)
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46960 is a privilege-escalation-adjacent vulnerability rooted in improper access controls (CWE-284) within the Internal Operations component of Oracle Project Portfolio Analysis. The vulnerability is easily exploitable—meaning the attack vector is straightforward—via HTTP network access. An attacker holding high-privileged credentials can bypass or circumvent intended authorization checks to gain complete control over the application, affecting all data confidentiality, integrity, and availability. The CVSS 3.1 score of 7.2 reflects the high impact across all three security properties, though the requirement for elevated starting privileges limits the attack surface.
Business impact
Compromise of Oracle Project Portfolio Analysis can result in unauthorized access to sensitive project data, including financial forecasts, resource allocations, and strategic planning information. Attackers could modify project portfolios, budgets, or resource assignments, leading to operational disruption and incorrect business decisions. In regulated environments, such a breach may trigger compliance violations (SOX, HIPAA, industry-specific mandates) and trigger disclosure obligations. The reputational and financial cost of a known supply-chain tool compromise extends beyond the immediate system to customer and partner confidence.
Affected systems
Oracle E-Business Suite deployments running Project Portfolio Analysis versions 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, or 12.2.15 are in scope. Organizations using Project Portfolio Analysis as a critical portfolio-management component are at elevated risk. The vulnerability does not affect later major versions, so upgrade paths exist. Organizations running unsupported or end-of-life versions bear additional risk.
Exploitability
The vulnerability is classified as easily exploitable but requires the attacker to already possess high-level privileges within the Oracle E-Business Suite environment. This is a critical distinction: the threat is not a zero-privilege remote attack. However, insider threats—including compromised administrator accounts, former employees with retained access, or lateral movement by an attacker who has compromised another E-Business Suite component—can readily exploit this flaw. No user interaction is required, and the attack is conducted via standard HTTP, making it straightforward once access prerequisites are met. The vulnerability is not currently tracked in the CISA Known Exploited Vulnerabilities catalog.
Remediation
Organizations must apply Oracle's security patch for Project Portfolio Analysis as soon as practical. Verify the specific patched version number and compatibility in the Oracle Critical Patch Update (CPU) advisory. As an interim control, restrict network access to Project Portfolio Analysis to only authorized administrative users and systems, implement rigorous access controls to limit the number of high-privileged accounts, and enforce multi-factor authentication for administrative access. Monitor audit logs for unauthorized access attempts or privilege escalation activity.
Patch guidance
Consult the Oracle Critical Patch Update advisory released on or around June 17, 2026, for the exact patched version number and installation instructions. Verify that the patch applies to your specific version (12.2.3–12.2.15). Test patches in a non-production environment before deployment to ensure no regressions in project portfolio workflows or integrations. Organizations should prioritize patching for instances exposed to untrusted networks or those with a large number of administrative users.
Detection guidance
Monitor authentication logs for failed or successful login attempts to Project Portfolio Analysis using high-privileged accounts, particularly from unexpected IP addresses or during off-hours. Review audit trails for unusual administrative actions such as bulk modifications to projects, portfolios, or budget data, or creation of new privileged accounts. Network intrusion detection systems should flag suspicious HTTP transactions to Project Portfolio Analysis endpoints. Consider deploying user-and-entity-behavior analytics (UEBA) to baseline normal administrative behavior and surface anomalies. Check for unusual API calls or direct database access patterns if Project Portfolio Analysis connects to other E-Business Suite modules.
Why prioritize this
This vulnerability merits immediate attention due to its HIGH CVSS severity (7.2), impact on all three security pillars (confidentiality, integrity, availability), and the strategic importance of portfolio-management tools in enterprise decision-making. While the requirement for high-privileged access limits the immediate threat surface, insider risk, account compromise, and lateral movement justify swift patching. Organizations with mature access-control practices may deprioritize marginally, but those with a large number of administrative accounts or legacy identity-governance controls should treat this as critical.
Risk score, explained
The CVSS 3.1 score of 7.2 reflects an easily exploitable attack vector (AV:N), low attack complexity (AC:L), and high impact on confidentiality, integrity, and availability (C:H, I:H, A:H). The score is not higher because the vulnerability requires high privilege level (PR:H) as a prerequisite, narrowing the population of potential attackers. The scope is unchanged (S:U), meaning only the vulnerable component is affected. The rating aligns with high-risk vulnerabilities that demand timely patching but are not in the critical tier.
Frequently asked questions
Do I need to patch if we have strong network segmentation and limits on administrative accounts?
Network segmentation and administrative access restrictions are valuable defenses, but they are not substitutes for patching. Compromised credentials, insider threats, and lateral movement can still enable exploitation. Patching closes the vulnerability entirely and should be the primary remediation.
Are later versions of Oracle E-Business Suite immune to this issue?
This CVE affects versions 12.2.3–12.2.15 of Project Portfolio Analysis. Customers on later major versions should verify coverage in the Oracle advisory. However, always assume a newer version is not affected unless explicitly confirmed; do not rely on version assumptions alone.
What is the difference between this vulnerability and other Oracle E-Business Suite issues?
This vulnerability is specific to the Project Portfolio Analysis internal operations component and requires high-level privilege to exploit. It is not a general E-Business Suite flaw and does not affect all E-Business Suite customers—only those running the affected versions of the Portfolio Analysis module.
Will this vulnerability appear in CISA's Known Exploited Vulnerabilities (KEV) catalog?
As of the current data, CVE-2026-46960 is not listed in the CISA KEV catalog and shows no ransomware association. However, status can change if active exploitation is observed in the wild. Monitor CISA and vendor advisories for updates.
This analysis is provided for informational purposes and does not constitute legal, compliance, or professional security advice. Organizations should verify all patch versions, affected product configurations, and compatibility with their specific deployments by consulting the Oracle Critical Patch Update advisory and their own security and operations teams. The vulnerability is not currently tracked in CISA's Known Exploited Vulnerabilities catalog; however, threat status may change. SEC.co makes no guarantee regarding the completeness or real-time accuracy of threat intelligence and recommends continuous monitoring of official vendor advisories and threat feeds. Source: NVD (public-domain), retrieved 2026-07-26. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35262HIGHOracle Data Integrator Authentication Bypass – Data Exposure Risk
- CVE-2026-35269HIGHOracle Identity Manager REST WebServices Authentication Bypass
- CVE-2026-35271HIGHOracle PeopleSoft WebLogic Unauthenticated Data Access Vulnerability (CVSS 8.7)
- CVE-2026-35275HIGHOracle VM VirtualBox Shared Folders Privilege Escalation Vulnerability (CVSS 7.5)
- CVE-2026-35277HIGHOracle REST Data Services Authorization Bypass
- CVE-2026-35311HIGHOracle WebLogic Server Remote Takeover via Low-Privilege Access Control Flaw
- CVE-2026-35314HIGHOracle Access Manager Authentication Bypass (CVSS 7.3)
- CVE-2026-35315HIGHOracle WebCenter Content Remote Takeover via Low-Privilege HTTP Access