CVE-2026-46918: Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. While the vulnerability is in Oracle Process Manufacturing Product Development, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Product Development. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 9.9
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A critical-severity authentication-partial-bypass leading to full system takeover affects Oracle Process Manufacturing Product Development, a component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is reachable over the network via HTTP by any low-privileged authenticated user, requires no victim interaction, and carries a scope-change designation meaning exploitation can spill into adjacent systems beyond the directly targeted component. Successful exploitation gives an attacker complete control over the affected installation, including full read, write, and availability impact. HarborGuard tracks this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Oracle E-Business Suite components.
AvailableHarborGuard scores this finding at CVSS 9.9 (Critical) and weighs it against each environment's compliance policy to determine priority routing; alerts are directed to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableBecause Oracle has not yet published a fix version, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will be initiated without manual intervention once a fix version is confirmed.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle E-Business Suite HTTP endpoint over the network; there is no local or physical access requirement.
- AuthenticationRequired
Any low-privilege account is sufficient; no administrative credentials are needed to trigger the vulnerability.
- Victim interactionNot required
No user action or social engineering is needed; the attacker can exploit the vulnerability entirely on their own.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other environmental factors.
Blast Radius
- A successful attacker reads all data accessible to the Oracle Process Manufacturing Product Development component, including process formulas, batch records, and any credentials or tokens stored within the application.
- The attacker can write or modify persisted manufacturing and product development records, corrupting production data or injecting malicious configuration.
- The attacker can crash or deny availability of the Oracle Process Manufacturing Product Development service, halting manufacturing operations.
- Because the CVSS vector carries a scope change, the attacker can pivot from the compromised component into other products sharing the same E-Business Suite environment, extending impact beyond the initial target.
How HarborGuard Handles This
Available on HarborGuard: because no fix version has been published by Oracle, HarborGuard continuously monitors the advisory and re-evaluates affected images on every ingest cycle. As a compensating control while waiting for an upstream patch, customers can apply network-policy isolation to restrict HTTP access to the Oracle E-Business Suite Internal Operations component to only explicitly authorized internal IP ranges, apply egress filtering to limit lateral movement if the component is compromised, and gate access to the affected functionality via application-layer feature flags or WAF rules where the deployment model permits. The moment Oracle ships a fix version, a patched-image rebuild becomes available on HarborGuard; for customers who opt into auto-remediation, that rebuild will be paired with a regression-test run and a PR opened against affected workloads automatically, with no manual trigger required.
- Oracle Corporation / Oracle Process Manufacturing Product Development≤ 12.2.15
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H