CVE-2026-46967: Oracle Public Sector Financials Authorization Bypass (CVSS 8.8)
A flaw in Oracle's Public Sector Financials (International) module, part of E-Business Suite, allows an authenticated attacker with basic network access to gain complete control over the application. The vulnerability exists in how the system handles user permissions and can be exploited without requiring user interaction. Attackers could read sensitive data, modify records, or disrupt service availability.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 8.8 HIGH · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-284
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-18
NVD description (verbatim)
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46967 is an authorization bypass vulnerability affecting Oracle Public Sector Financials (International) in E-Business Suite versions 12.2.3 through 12.2.15. The flaw stems from improper access control (CWE-284) that enables low-privileged users to escalate privileges and take over the application via HTTP requests. The attack requires network connectivity and valid authentication credentials but does not require any user action or unusual system configuration to succeed.
Business impact
For government and public sector organizations running Oracle E-Business Suite, this vulnerability poses a critical operational risk. Compromise of financials systems can lead to unauthorized fund transfers, falsification of financial records, audit trail tampering, and service outages affecting payment processing, budgeting, and compliance reporting. The impact extends beyond confidentiality to include integrity and availability, making this a full system takeover threat that could affect procurement, payroll, and revenue operations.
Affected systems
Oracle E-Business Suite installations with the Public Sector Financials (International) module are vulnerable if running version 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, or 12.2.15. Organizations using other E-Business Suite modules without this specific component are not affected. Verify your installed version and module configuration to determine exposure.
Exploitability
The vulnerability rates highly exploitable due to low attack complexity, network-only requirements, and the broad base of authenticated users who could serve as attack entry points. Once an attacker gains even basic user access—through credential compromise, insider action, or initial phishing—escalation to full system control requires only crafted HTTP requests. The absence of any user interaction requirement or additional exploitation steps makes this particularly dangerous in environments with many active users or where credential compromise is difficult to prevent.
Remediation
Apply Oracle's security updates as published in their official Critical Patch Update (CPU) advisory for the affected release. Verify patch applicability before deployment by consulting the vendor's patch matrix. Interim mitigations include restricting network access to E-Business Suite HTTP interfaces, implementing strict role-based access controls to limit low-privileged user account capabilities, conducting credential audits to reduce the number of active user accounts, and monitoring for suspicious authentication patterns and privilege escalation attempts.
Patch guidance
Oracle has released patches addressing this vulnerability. Consult the official Oracle Security Alert (published 2026-06-17) and associated Critical Patch Update documentation to identify the correct patch version for your specific E-Business Suite release line. Test patches in a non-production environment before applying to production financials systems, given the critical nature of these systems. Coordinate patch timing with your financial close calendar and backup procedures.
Detection guidance
Monitor HTTP logs for unusual authorization-related errors or access attempts from low-privileged user accounts targeting administrative or sensitive financial functions. Look for privilege escalation patterns such as rapid role changes or permission modifications. Examine database audit logs for unexpected changes to financial records, GL entries, or payment data initiated by standard users. Implement alerting on failed authorization checks and successful access to out-of-role transactions. Consider scanning active sessions for users with unexpectedly elevated permissions.
Why prioritize this
This vulnerability merits immediate attention due to the combination of high exploitability, broad impact scope (confidentiality, integrity, availability), and the critical nature of financial systems. The low barrier to exploitation—only requiring network access and low-level user credentials—makes it particularly suitable for insider threats or follow-up attacks after initial compromise. Public sector financials systems are often high-value targets for fraud and espionage, and the potential for undetected financial manipulation creates both operational and compliance risk.
Risk score, explained
The CVSS 3.1 score of 8.8 (HIGH) reflects the combination of network-accessible attack vector, low complexity, and full system compromise potential despite requiring authentication. The score weights heavily toward impact (confidentiality, integrity, and availability all rated high), balanced only by the requirement for prior authentication. The severity is appropriate for a flaw that enables full takeover of a critical financial application once any valid user credential is obtained.
Frequently asked questions
Our organization uses Oracle E-Business Suite but not the Public Sector Financials International module. Are we affected?
No. This vulnerability is specific to the Public Sector Financials (International) component. Other E-Business Suite modules, even in the same installation, are not affected by this flaw. Verify your module inventory to confirm.
Can an attacker exploit this without any user credentials?
No. The vulnerability requires the attacker to already possess valid login credentials for at least a low-privileged user account. This is why credential compromise and insider threat scenarios are the primary exploitation vectors. Securing user credentials and monitoring for unusual account activity are therefore critical defenses.
What should we prioritize if we cannot patch immediately?
First, restrict network access to your E-Business Suite HTTP interfaces using firewalls or VPN requirements. Second, audit and disable unnecessary user accounts. Third, implement strict monitoring of privilege escalation and financial transaction changes. Fourth, prepare an offline backup and ensure you can detect unauthorized changes to financial records. However, patching should be your primary goal; these are temporary compensating controls only.
How does this differ from typical authorization vulnerabilities?
The severity here stems from the combination of (1) an easily exploitable flaw with (2) no user interaction needed and (3) application to critical financial systems where data integrity is paramount. Even many authorization flaws require some additional complexity or offer limited impact; this one directly enables full system compromise via standard network protocols.
This analysis is based on Oracle's official CVE disclosure and CVSS vector as of June 2026. Patch availability, version applicability, and remediation timelines should be verified against current Oracle Security Alerts and Critical Patch Update advisories. This content is for informational purposes and does not constitute professional security advice. Organizations should engage qualified security and database administrators to assess exposure and plan remediation in their specific environment. No proof-of-concept code or active exploitation details are provided; this summary is intended to inform defensive decision-making only. Source: NVD (public-domain), retrieved 2026-07-26. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35262HIGHOracle Data Integrator Authentication Bypass – Data Exposure Risk
- CVE-2026-35269HIGHOracle Identity Manager REST WebServices Authentication Bypass
- CVE-2026-35271HIGHOracle PeopleSoft WebLogic Unauthenticated Data Access Vulnerability (CVSS 8.7)
- CVE-2026-35275HIGHOracle VM VirtualBox Shared Folders Privilege Escalation Vulnerability (CVSS 7.5)
- CVE-2026-35277HIGHOracle REST Data Services Authorization Bypass
- CVE-2026-35311HIGHOracle WebLogic Server Remote Takeover via Low-Privilege Access Control Flaw
- CVE-2026-35314HIGHOracle Access Manager Authentication Bypass (CVSS 7.3)
- CVE-2026-35315HIGHOracle WebCenter Content Remote Takeover via Low-Privilege HTTP Access