HarborGuard / CVE
Back to search
HIGHCVE-2026-46828Published Modified CNA oracle

CVE-2026-46828: Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payroll accessible data as well as unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

HarborGuard Analysis

HarborGuard analysis

Synopsis

An unauthorized-access vulnerability affects the Internal Operations component of Oracle Payroll within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is reachable over HTTP from any network and requires only a low-privilege account, with no interaction from other users needed. Successful exploitation gives an attacker full read access to all Oracle Payroll data as well as the ability to create, modify, or delete that data. HarborGuard is tracking this advisory and will make a patched-image rebuild available as soon as Oracle publishes a fix version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle E-Business Suite components. Any image running an affected Oracle Payroll version (12.2.3 through 12.2.15) is flagged automatically in both registry scans and CI/CD pipeline checks.

Available
Triage

HarborGuard is capable of scoring this finding at its published CVSS 3.1 severity of 8.1 (High) and weighting it further against each customer environment's compliance policy. Routed findings land in the appropriate team inbox within the customer org based on policy-defined ownership rules.

Available
Patch

No fix version has been published by Oracle for this CVE. HarborGuard re-checks the upstream advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle ships a fix. For customers with auto-remediation enabled, the rebuild, regression run, and PR against affected workloads will be initiated automatically once a fix version becomes available.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle Payroll service over the network via HTTP; the vulnerability is exposed on any network-accessible instance.

  • AuthenticationRequired

    A valid low-privilege account is sufficient; no administrative or elevated credentials are needed beyond basic authenticated access.

  • Victim interactionNot required

    No action from another user or administrator is needed to complete the attack.

  • Attack complexityDetail

    Attack complexity is Low, meaning the exploit is reliable and requires no special conditions, race wins, or environmental setup.

Blast Radius

  • An attacker reads all data accessible to Oracle Payroll, including employee compensation records, payroll runs, tax details, and banking information.
  • An attacker creates, modifies, or deletes payroll records, potentially corrupting pay cycles or injecting fraudulent payment entries.
  • Sensitive HR and financial data exposed through Oracle Payroll is fully readable without any additional privilege escalation steps.
  • Integrity loss extends to all Oracle Payroll-accessible data, meaning audit trails and compliance records can be altered or destroyed.

How HarborGuard Handles This

Available on HarborGuard: this CVE is actively tracked with no fix version yet published by Oracle. On every ingest cycle, HarborGuard re-checks the Oracle and NVD advisory feeds so that a patched-image rebuild becomes available automatically the moment Oracle ships a corrected version. For customers with auto-remediation enabled, that sequence includes a full regression run and a PR opened against affected workloads, typically completing within approximately 90 minutes of a fix appearing upstream for high-severity issues. While no upstream patch exists, compensating controls available to consider include network-policy isolation to restrict HTTP access to Oracle Payroll endpoints to known trusted source IPs, egress filtering to limit lateral movement from a compromised Payroll instance, and feature-flag or WAF-rule gating on the Internal Operations component endpoints. Customers whose compliance policy flags unpatched High-severity CVEs will see this finding routed automatically to the appropriate team inbox for review and manual remediation planning.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.1
Severity
HIGH
Fixed in
Affected Products
1
Affected packages
  • Oracle Corporation / Oracle Payroll
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
References