CVE-2026-46819: Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
HarborGuard Analysis
HarborGuard analysisSynopsis
An authentication bypass and data-exposure vulnerability affects the Internal Operations component of Oracle Internet Procurement Connector, part of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw is reachable over HTTP from any network without authentication, and requires no user interaction to trigger. Successful exploitation grants an attacker full read access to all data the connector can reach, plus the ability to create, modify, or delete critical records. HarborGuard tracks this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix version.
HarborGuard Coverage
Detection of CVE-2026-46819 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Oracle E-Business Suite components.
AvailableHarborGuard is capable of scoring this finding at CVSS 9.1 (Critical) and weighting it against each environment's compliance policy to prioritize routing; affected findings can be directed to the appropriate team inbox within each customer organization based on configured policy rules.
AvailableBecause no fix version has been published by Oracle, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, a rebuilt image, regression-test run, and a PR opened against affected workloads will be triggered without manual intervention once a fix version becomes available.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must be able to reach the Oracle Internet Procurement Connector service over a network via HTTP; no local or physical access is needed, making internet-exposed or internally networked instances directly at risk.
- AuthenticationNot required
No credentials of any privilege level are needed; an unauthenticated attacker can send malicious requests directly to the exposed endpoint.
- Victim interactionNot required
The attack is fully server-side and requires no action from any user or administrator on the target system.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and imposes no special preconditions such as race conditions, memory layout dependencies, or configuration prerequisites.
Blast Radius
- Reads all data accessible to Oracle Internet Procurement Connector, including procurement records, supplier data, and any credentials or tokens stored within the component.
- Creates, modifies, or deletes critical procurement records and associated data across all versions 12.2.3 through 12.2.15.
- May allow an attacker to tamper with purchasing workflows or inject fraudulent purchase orders into downstream Oracle E-Business Suite processes.
- Availability of the service is not directly impacted according to the CVSS vector, but data integrity and confidentiality are fully compromised.
How HarborGuard Handles This
Available on HarborGuard: this CVE is monitored on every ingest cycle because Oracle has not yet published a fix version. As soon as Oracle releases a patched version, a rebuilt image at that version becomes available, and customers with auto-remediation enabled will receive a rebuilt image, a regression-test run, and a PR opened against affected workloads automatically. In the interim, HarborGuard recommends applying compensating controls where possible: restrict network access to the Oracle Internet Procurement Connector endpoint using Kubernetes NetworkPolicy or equivalent firewall rules to limit exposure to trusted internal subnets only; apply egress filtering to prevent the component from initiating outbound connections to untrusted hosts; and consider feature-flag gating or disabling the Internal Operations endpoint if it is not actively required. The advisory will continue to surface in each affected customer environment's findings feed until a patched rebuild is confirmed clean and merged.
Metrics
- CVSS v3.1
- 9.1
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
- Oracle Corporation / Oracle Internet Procurement Connector≤ 12.2.15
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N