CVE-2026-46929: Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning)
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An unspecified vulnerability in the Cost Planning component of Oracle Cost Management (part of Oracle E-Business Suite, versions 12.2.3 through 12.2.15) is reachable over the network via HTTP. An attacker holding any low-privilege account can exploit it without requiring additional user interaction. Successful exploitation results in full takeover of Oracle Cost Management, giving the attacker read, write, and denial-of-service control over the affected instance. HarborGuard tracks this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images, including custom-built images derived from Oracle E-Business Suite base layers. Any image running an affected version of Oracle Cost Management (12.2.3 through 12.2.15) is flagged automatically in both registry scans and CI/CD pipeline checks.
AvailableHarborGuard surfaces this vulnerability with its CVSS 3.1 base score of 8.8 (HIGH) and applies each customer organization's compliance policy weighting to prioritize it appropriately within that environment's risk queue. Routed findings are directed to the relevant team inbox based on image ownership and policy configuration inside each customer org.
AvailableNo fix version has been published by Oracle at this time; HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and pull request against affected workloads will be initiated without manual intervention as soon as a fix version becomes available.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle Cost Management service over the network via HTTP; no local or physical access is needed.
- AuthenticationRequired
Any low-privilege account is sufficient; the attacker does not need administrative or elevated credentials.
- Victim interactionNot required
No action from any user or administrator is needed to trigger the vulnerability.
- Attack complexityDetail
Exploitation is reliable and condition-free; no race conditions, special memory layouts, or environmental prerequisites are required.
Blast Radius
- Reads all data accessible to Oracle Cost Management, including cost plans, pricing records, and any stored credentials or session tokens within the application.
- Modifies or deletes cost planning records and persisted application data, enabling financial data manipulation.
- Crashes or degrades the Oracle Cost Management service, disrupting cost planning operations for all users of the affected instance.
- Achieves full application-level takeover, meaning an attacker can chain access to other E-Business Suite components reachable from the compromised service.
How HarborGuard Handles This
Available on HarborGuard: this CVE is actively tracked with no fix version currently published by Oracle. Because no patched base image exists yet, HarborGuard re-evaluates the advisory on every ingest cycle so that a rebuild becomes available the moment Oracle ships a fix. In the interim, compensating controls worth considering include restricting network-policy rules to limit HTTP access to Oracle Cost Management to known-good source IP ranges, applying egress filtering to reduce lateral movement potential from a compromised instance, and using feature-flag or role-based gating to limit Cost Planning access to the smallest necessary set of accounts. For customers with auto-remediation enabled, once Oracle publishes a fix, HarborGuard will initiate a patched-image rebuild, run regression tests, and open a pull request against affected workloads without requiring manual steps. Where compliance policy permits this automated flow, median time from CVE patch availability to a merged patch PR for high-severity issues is around 90 minutes.
- Oracle Corporation / Oracle Cost Management≤ 12.2.15
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H