CVE-2026-46915
Awaiting Analysis Awaiting Analysis - Queue
Oracle E-Business Suite CMRO Privilege Escalation

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
oracle complex_maintenance_repair_and_overhaul From 12.2.3 (inc) to 12.2.15 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the Oracle Complex Maintenance, Repair and Overhaul product of the Oracle E-Business Suite, specifically affecting versions 12.2.3 through 12.2.15. It is a difficult to exploit vulnerability that allows a low privileged attacker with network access via HTTP to compromise the product.

Although the vulnerability is within the Oracle Complex Maintenance, Repair and Overhaul component, successful exploitation can lead to a takeover of this product and may also significantly impact additional Oracle products due to scope change.

Impact Analysis

Successful exploitation of this vulnerability can result in a complete takeover of the Oracle Complex Maintenance, Repair and Overhaul product.

The impacts include severe confidentiality, integrity, and availability losses, meaning sensitive data could be exposed or altered, and the availability of the service could be disrupted.

Additionally, because the scope of the attack can extend beyond this product, other Oracle products may also be significantly affected.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46915. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart