HarborGuard / CVE
Back to search
CRITICALCVE-2026-46819Published Modified CNA oracle

CVE-2026-46819: Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Internet Procurement Connector accessible data as well as unauthorized access to critical data or complete access to all Oracle Internet Procurement Connector accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).

HarborGuard Analysis

HarborGuard analysis

Synopsis

An authentication bypass and data-exposure vulnerability affects the Internal Operations component of Oracle Internet Procurement Connector, part of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw is reachable over HTTP from any network without authentication, and requires no user interaction to trigger. Successful exploitation grants an attacker full read access to all data the connector can reach, plus the ability to create, modify, or delete critical records. HarborGuard tracks this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix version.

HarborGuard Coverage

Detection

Detection of CVE-2026-46819 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Oracle E-Business Suite components.

Available
Triage

HarborGuard is capable of scoring this finding at CVSS 9.1 (Critical) and weighting it against each environment's compliance policy to prioritize routing; affected findings can be directed to the appropriate team inbox within each customer organization based on configured policy rules.

Available
Patch

Because no fix version has been published by Oracle, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, a rebuilt image, regression-test run, and a PR opened against affected workloads will be triggered without manual intervention once a fix version becomes available.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must be able to reach the Oracle Internet Procurement Connector service over a network via HTTP; no local or physical access is needed, making internet-exposed or internally networked instances directly at risk.

  • AuthenticationNot required

    No credentials of any privilege level are needed; an unauthenticated attacker can send malicious requests directly to the exposed endpoint.

  • Victim interactionNot required

    The attack is fully server-side and requires no action from any user or administrator on the target system.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and imposes no special preconditions such as race conditions, memory layout dependencies, or configuration prerequisites.

Blast Radius

  • Reads all data accessible to Oracle Internet Procurement Connector, including procurement records, supplier data, and any credentials or tokens stored within the component.
  • Creates, modifies, or deletes critical procurement records and associated data across all versions 12.2.3 through 12.2.15.
  • May allow an attacker to tamper with purchasing workflows or inject fraudulent purchase orders into downstream Oracle E-Business Suite processes.
  • Availability of the service is not directly impacted according to the CVSS vector, but data integrity and confidentiality are fully compromised.

How HarborGuard Handles This

Available on HarborGuard: this CVE is monitored on every ingest cycle because Oracle has not yet published a fix version. As soon as Oracle releases a patched version, a rebuilt image at that version becomes available, and customers with auto-remediation enabled will receive a rebuilt image, a regression-test run, and a PR opened against affected workloads automatically. In the interim, HarborGuard recommends applying compensating controls where possible: restrict network access to the Oracle Internet Procurement Connector endpoint using Kubernetes NetworkPolicy or equivalent firewall rules to limit exposure to trusted internal subnets only; apply egress filtering to prevent the component from initiating outbound connections to untrusted hosts; and consider feature-flag gating or disabling the Internal Operations endpoint if it is not actively required. The advisory will continue to surface in each affected customer environment's findings feed until a patched rebuild is confirmed clean and merged.

See how HarborGuard automates this

Metrics

CVSS v3.1
9.1
Severity
CRITICAL
Fixed in
Affected Products
1
Affected packages
  • Oracle Corporation / Oracle Internet Procurement Connector
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
References
CVE-2026-46819: Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations) | HarborGuard CVE