CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46946

Critical · CVSS 9.1

Oracle iSupport (Oracle E-Business Suite) — Improper Access Control / Authorization Bypass leading to full product takeover (CWE-284)

CVSS
9.1
nvd
EPSS
KEV
No
Class
other
NVD-CWE-noinfo, CWE-284

Description

Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. While the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols iSupportInternal OperationsOracle E-Business SuiteEBSIBUiSupport componentHTTP network access
Keywords CVE-2026-46946Oracle iSupportE-Business Suite iSupport exploitOracle EBS 12.2 iSupport PoCiSupport Internal Operations vulnerabilityOracle EBS access control bypassOracle iSupport takeoverOracle CPU June 2026 iSupportCWE-284 Oracle EBS
Versions: 12.2.3 - 12.2.15

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z