CVE-2026-46837: Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security)
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in takeover of Oracle Flow Manufacturing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
HarborGuard Analysis
HarborGuard analysisSynopsis
A SQL-based vulnerability in the Security component of Oracle Flow Manufacturing (part of Oracle E-Business Suite, versions 12.2.9 through 12.2.15) allows a low-privileged, authenticated attacker to reach the product over the network and fully compromise it. No victim interaction is required, and the exploit is straightforward enough that Oracle rates it as easily exploitable. Successful exploitation gives the attacker full control over the affected Oracle Flow Manufacturing instance, covering data read, data write, and service availability. No fix version has been published yet; HarborGuard is actively tracking the advisory for patch availability.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against customer images in both registries and CI/CD pipelines, including custom-built images that bundle Oracle E-Business Suite components. Any image running an affected Oracle Flow Manufacturing version (12.2.9 through 12.2.15) is flagged automatically.
AvailableHarborGuard scores this issue at CVSS 8.8 HIGH (v3.1) and is capable of weighting that score against each customer environment's compliance policy to adjust priority accordingly. Triage findings are routed to the inbox or ticketing integration configured for the relevant team within each customer organization.
AvailableBecause no upstream fix has been published, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle ships a remediated version. In the meantime, customers can apply compensating controls directly through HarborGuard's policy engine, such as network-policy isolation for affected workloads or egress filtering on SQL-accessible endpoints.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must be able to reach the Oracle Flow Manufacturing service over the network via SQL; there is no local-only constraint.
- AuthenticationRequired
Any low-privilege account on the system is sufficient; no administrative credentials are needed.
- Victim interactionNot required
The attacker does not need to involve or trick any other user to carry out the attack.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory layout knowledge, or other environmental prerequisites.
Blast Radius
- A successful attacker reads all data accessible to the Oracle Flow Manufacturing application, including production schedules, bills of materials, work orders, and any credentials or session tokens stored in the database.
- The attacker can write or modify persisted records in Oracle Flow Manufacturing, altering manufacturing plans, work-in-progress data, or routing configurations.
- The attacker can crash or render the Oracle Flow Manufacturing service unavailable, disrupting production planning and shop-floor execution workflows.
- Because the CVSS scope is full system takeover, the attacker gains the ability to pivot from the compromised application tier to any backend database or adjacent E-Business Suite component the application account can reach.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46837, HarborGuard continuously re-ingests the Oracle advisory on every feed cycle and will surface a patched-image rebuild the moment a remediated version is released. Until then, customers can use HarborGuard's policy engine to flag images running Oracle Flow Manufacturing 12.2.9 through 12.2.15 and enforce compensating controls such as network-policy isolation (restricting SQL-port access to authorized internal hosts only), egress filtering on the application tier, and feature-flag or WAF-level gating on the affected Security component endpoints. For customers with auto-remediation enabled, a rebuilt image, regression-test run, and a PR opened against affected workloads will be triggered automatically as soon as an upstream fix is available, with a typical median time from CVE publication to merged patch PR of around 90 minutes for HIGH-severity issues once a fix version is published.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
- Oracle Corporation / Oracle Flow Manufacturing≤ 12.2.15
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H