HIGH 8.8

CVE-2026-46961: Oracle Project Portfolio Analysis Privilege Escalation (CVSS 8.8)

A critical vulnerability in Oracle Project Portfolio Analysis allows authenticated users with basic network access to gain full control over the application. An attacker with a low-privilege account can exploit this flaw to read, modify, or delete sensitive project data and disrupt service availability. The vulnerability affects multiple versions of the product (12.2.3 through 12.2.15) and requires only HTTP connectivity—no special conditions or user interaction needed once the attacker gains initial access credentials.

Source data · NVD / CISA · public domain

CVSS
3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-269, CWE-287, CWE-306
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-18

NVD description (verbatim)

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-46961 represents an improper access control issue in Oracle E-Business Suite's Project Portfolio Analysis module. The vulnerability stems from inadequate privilege verification and session management controls, allowing authenticated users to escalate their capabilities and assume full administrative authority over the system. With a CVSS 3.1 score of 8.8 (High severity), the attack vector is network-based, attack complexity is low, and no user interaction is required. The underlying weaknesses map to improper privilege management (CWE-269), broken authentication (CWE-287), and missing access control validation (CWE-306). The impact scope is unchanged (limited to the affected component), but confidentiality, integrity, and availability are all fully compromised.

Business impact

Compromise of Project Portfolio Analysis can expose sensitive project timelines, resource allocations, budget data, and strategic planning information to unauthorized internal or external attackers. Organizations using this module for portfolio governance face potential data theft, project delays due to malicious modifications, and operational disruption. In regulated industries, unauthorized access to project data may trigger compliance violations and reporting obligations. The low barrier to exploitation—requiring only low-privilege credentials—means the attack surface includes any user with basic system access, significantly expanding organizational risk.

Affected systems

Oracle E-Business Suite versions 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, and 12.2.15 are vulnerable when Project Portfolio Analysis is deployed. Patches addressing this vulnerability should be confirmed against the official Oracle Critical Patch Update (CPU) advisories. Organizations should verify whether Project Portfolio Analysis is active in their E-Business Suite instances and inventory all affected versions in use.

Exploitability

This vulnerability is easily exploitable by attackers with low-privilege network access to the application. No special technical skills, complex exploitation chains, or social engineering are required; a valid set of credentials—such as those obtained through credential reuse, phishing, or insider access—combined with HTTP network connectivity is sufficient. The low attack complexity and lack of user interaction requirements mean this flaw can be weaponized quickly. However, the vulnerability is not yet in the CISA Known Exploited Vulnerabilities (KEV) catalog, so active in-the-wild exploitation has not been publicly documented at the time of publication.

Remediation

Organizations should prioritize applying Oracle's official patches for this vulnerability immediately. Verify the patch version available in Oracle's latest Critical Patch Update or security advisory against your current E-Business Suite version. Additionally, implement network segmentation to restrict HTTP access to Project Portfolio Analysis to authorized users and systems only. Review access logs and authentication records for suspicious low-privilege account activity. Consider temporarily disabling non-essential Project Portfolio Analysis features until patching is complete. For organizations unable to patch immediately, enforce additional access controls such as multi-factor authentication for Project Portfolio Analysis users and restrict API endpoints where possible.

Patch guidance

Obtain the latest critical patch from Oracle's official CPU advisory page. Patches should be applied in a controlled manner, beginning with non-production environments to validate compatibility with existing extensions and customizations. Test functionality in staging before production deployment to ensure no regression in reporting or data integrity. Coordinate with project portfolio teams to schedule maintenance windows that minimize business impact. Verify patch application by checking the applied patch level and confirming that access control enforcement is active. After patching, re-test access controls to ensure low-privilege accounts no longer retain escalated permissions.

Detection guidance

Monitor authentication and authorization logs in E-Business Suite for anomalous patterns, including low-privilege accounts accessing Project Portfolio Analysis administrative functions or APIs they should not have permission to use. Look for unusual network traffic from internal users directed at the application's HTTP endpoints. Track changes to project records, resource assignments, or budget data that originate from low-privilege accounts. Implement alerting on privilege escalation attempts or role assignment changes. Conduct periodic access reviews to identify users with excessive permissions in Project Portfolio Analysis and remediate misconfigurations immediately. Correlate Project Portfolio Analysis logs with identity and access management systems to detect credential misuse or unusual login patterns.

Why prioritize this

This vulnerability should be treated as critical priority due to its high CVSS score (8.8), full impact on confidentiality, integrity, and availability, and the low barrier to exploitation. Any authenticated user can trigger the flaw, and successful exploitation results in complete system compromise. Organizations relying on Project Portfolio Analysis for governance, resource planning, or budget management face immediate risk of data theft, unauthorized modifications, and service disruption. The vulnerability's presence across a wide range of supported versions (13 versions) increases the likelihood that organizations are running vulnerable instances. Early patching directly reduces exposure window.

Risk score, explained

The CVSS 3.1 base score of 8.8 (High) reflects the combination of network accessibility, low attack complexity, low privilege requirements, and full impact across all three security dimensions (confidentiality, integrity, availability). While the scope is unchanged and user interaction is not needed, the core weakness—improper access control—is a foundational security control; its failure permits complete takeover of the affected application and any data it manages. Organizations with strict data governance or regulatory requirements should further elevate this risk internally, as unauthorized access to project portfolio data may trigger audit exceptions or compliance violations.

Frequently asked questions

Do I need to apply this patch to all E-Business Suite instances?

You only need to patch if you have Project Portfolio Analysis actively deployed and are running one of the affected versions (12.2.3–12.2.15). Review your Oracle E-Business Suite module inventory to confirm. If Project Portfolio Analysis is not in use, this vulnerability does not affect your environment.

Can an attacker exploit this without a valid user account?

No. The vulnerability requires low-privilege network access via HTTP, meaning the attacker must first possess valid credentials or session tokens. However, many organizations have broad user bases with basic system access, making credential acquisition a realistic precondition. Implement strong authentication and access governance to reduce the pool of accounts that could be compromised.

What should I do if I cannot patch immediately?

Implement compensating controls: restrict network access to Project Portfolio Analysis using firewall rules or web application firewall policies, enforce multi-factor authentication for all users accessing the application, review and remove unnecessary user accounts or role assignments, and increase logging and monitoring for suspicious activity. These measures reduce risk but do not eliminate the underlying flaw—patching remains the primary remediation.

Is this vulnerability being actively exploited?

As of the publication date, this vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the ease of exploitation and high impact mean it could be targeted by threat actors once widely understood. Do not rely on the absence of known exploits to delay patching; treat this as urgent based on the CVSS score and your environment's sensitivity.

This analysis is provided for informational purposes and does not constitute legal, security, or compliance advice. Organizations must verify all patch versions and guidance against official Oracle security advisories and their specific environment configuration. SEC.co does not recommend or endorse any specific patches or workarounds; conduct internal testing before deploying patches to production. Threat landscape and exploit status may change; consult official vendor advisories and threat intelligence sources for the most current information. Responsibility for security decisions and patch deployment remains with the organization and its security team. Source: NVD (public-domain), retrieved 2026-07-26. Analysis generated by SEC.co (claude-haiku-4-5).