CVE-2026-46897: Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core)
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
Metrics
- CVSS v3.1
- 9.9
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a critical-severity vulnerability in the Core component of Oracle Enterprise Command Center Framework, part of Oracle E-Business Suite (versions V15 and V16). It is reachable over the network via HTTP and requires only a low-privileged account, with no victim interaction needed; the scope of impact extends beyond the directly affected component to additional products. Successful exploitation gives an attacker full read and write access to all data accessible by the framework, plus the ability to partially disrupt service availability. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix.
HarborGuard Coverage
Detection of CVE-2026-46897 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Oracle E-Business Suite components.
AvailableHarborGuard is capable of scoring this finding at CVSS 9.9 (Critical) and weighting it against each environment's compliance policy to prioritize alert routing; findings are surfaced to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableBecause Oracle has not yet published a fix for this CVE, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix version is released. For customers who opt into auto-remediation, the rebuild, regression test run, and PR against affected workloads will be triggered without manual intervention once a fix is available.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must be able to reach the Oracle Enterprise Command Center Framework service over the network via HTTP; no local or physical access is required.
- AuthenticationRequired
Any low-privileged account is sufficient; the attacker does not need administrative or elevated credentials.
- Victim interactionNot required
No user interaction is needed; the attacker can exploit this vulnerability entirely without involving another person.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, special memory layouts, or other environmental factors.
Blast Radius
- Reads all data accessible to the Oracle Enterprise Command Center Framework, including critical business data stored in E-Business Suite.
- Creates, modifies, or deletes critical data records across the framework and potentially across other products in scope due to the scope-change characteristic of this vulnerability.
- Partially disrupts availability of the Oracle Enterprise Command Center Framework service, causing degraded or intermittent access for legitimate users.
- Impact extends beyond the directly compromised component; other Oracle E-Business Suite products sharing the environment can be affected.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46897, HarborGuard continuously monitors the upstream advisory and will surface a patched-image rebuild capability the moment a fix version is released. In the interim, customers are advised to consider network-policy controls that restrict HTTP access to Oracle Enterprise Command Center Framework endpoints to only authorized internal networks, apply egress filtering to limit lateral movement from a compromised instance, and audit low-privileged account assignments within the E-Business Suite environment to reduce the pool of accounts an attacker could leverage. For customers who opt into auto-remediation, the full rebuild, regression-test, and PR flow will trigger automatically once Oracle ships a patch, with no manual steps required.
- Oracle Corporation / Oracle Enterprise Command Center FrameworkV15 · V16
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L