CVE-2026-46915: Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production)
Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.5
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An unspecified high-severity vulnerability affects the Production component of Oracle Complex Maintenance, Repair and Overhaul (CMRO), part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is reachable over the network via HTTP and requires a low-privileged account, but exploitation is difficult due to environmental conditions the attacker must satisfy. Successful exploitation enables full takeover of the CMRO application, with scope change meaning attacks can spill over into additional products in the same environment. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: the CVE is ingested from Oracle and upstream vulnerability feeds within minutes of publication and matched against all customer images, including internally built images layering Oracle E-Business Suite components. Any image found running an affected CMRO version (12.2.3 through 12.2.15) is flagged automatically.
AvailableHarborGuard scores this finding at CVSS 8.5 (HIGH) and weights it against each customer environment's compliance policy, which may elevate priority further given the scope-change and full-takeover impact. Triage results are routed to the appropriate team inbox within each customer organization based on image ownership and policy configuration.
AvailableBecause Oracle has not yet published a fix version, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers who opt into auto-remediation, the rebuild, regression test run, and PR against affected workloads will be initiated without manual intervention once the patch is available.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the CMRO application over the network via HTTP; the service must be exposed to the attacker's network.
- AuthenticationRequired
A low-privilege account on the system is required; anonymous access alone is not sufficient to trigger the vulnerability.
- Victim interactionNot required
No action from a logged-in user or administrator is needed; the attacker can complete exploitation without social engineering.
- Attack complexityDetail
Exploitation is rated High complexity, meaning the attacker must meet specific environmental conditions or race conditions beyond simple network access, making reliable exploitation harder.
Blast Radius
- A successful attacker achieves full takeover of the CMRO application, gaining the ability to read all data stored within it, including maintenance records, repair orders, and overhaul schedules.
- The attacker can modify or delete persisted data within CMRO, tampering with production records and operational configurations.
- The CVSS scope change indicates the attacker can pivot to compromise additional Oracle E-Business Suite components running in the same environment.
- The availability impact is rated High, meaning the attacker can crash or render the CMRO service unavailable, disrupting production and maintenance operations.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a remediated version for CVE-2026-46915, the platform monitors the advisory on every ingest cycle and will surface a patched-image rebuild opportunity the moment Oracle ships a fix. In the interim, customers should consider applying network-policy controls to restrict HTTP access to CMRO endpoints to only known, authorized source IP ranges, reducing the pool of accounts that could reach the vulnerable component. Egress filtering on CMRO container workloads can also limit lateral movement in the event of a scope-change exploit. Where compliance policy supports it, feature-flag gating on the Production component is worth evaluating until a vendor patch is available. HarborGuard will generate a rebuild and, for customers with auto-remediation enabled, open a regression-tested PR against affected workloads as soon as the upstream fix is confirmed.
- Oracle Corporation / Oracle Complex Maintenance, Repair and Overhaul≤ 12.2.15
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H