HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46940Published Modified CNA oracle

CVE-2026-46940: Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning)

Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An unspecified high-severity vulnerability exists in the Cost Planning component of Oracle Cost Management, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is reachable over the network via HTTP and requires only a low-privileged account, with no user interaction needed. Successful exploitation gives an attacker full control over the affected Oracle Cost Management instance, impacting confidentiality, integrity, and availability. HarborGuard is tracking this advisory and will make a patched-image rebuild available as soon as Oracle publishes a fix version.

HarborGuard Coverage

Detection

Detection for CVE-2026-46940 is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Oracle E-Business Suite components. Any image running an affected version of Oracle Cost Management (12.2.3 through 12.2.15) is flagged automatically in both registry scans and CI/CD pipeline checks.

Available
Triage

HarborGuard surfaces this CVE with its CVSS 3.1 score of 8.8 (HIGH), and per-environment compliance policy weighting can escalate or suppress the finding based on each organization's risk thresholds. Triage alerts are routed to the inbox configured for the affected workload inside each customer org, so the right team sees the finding without manual filtering.

Available
Patch

Because no upstream fix version has been published by Oracle, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle releases a remediated version. In the interim, customers with auto-remediation enabled will receive a notification and can apply compensating controls through HarborGuard's policy engine while the patch is pending.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle Cost Management HTTP service over the network; no physical or local access is needed.

  • AuthenticationRequired

    Any low-privileged account with network access is sufficient; no administrative credentials are required.

  • Victim interactionNot required

    The attack completes without any action from a logged-in user or administrator.

  • Attack complexityDetail

    Exploitation is reliable and condition-free; no race conditions, memory layout dependencies, or special environmental factors are required.

Blast Radius

  • A successful attacker reads all data accessible to the Oracle Cost Management application, including cost plans, pricing records, and any credentials or session tokens stored within the component.
  • The attacker can modify or delete persisted cost and planning data, corrupting financial records and production cost calculations.
  • The attacker can crash or render the Oracle Cost Management service unavailable, disrupting procurement and manufacturing cost workflows.
  • Full application takeover means the attacker can pivot to other E-Business Suite components or backend database connections reachable from the compromised service.

How HarborGuard Handles This

Available on HarborGuard: CVE-2026-46940 is matched against images containing Oracle Cost Management 12.2.3 through 12.2.15 on every scan cycle, with findings surfaced at CVSS 8.8 HIGH severity. Because Oracle has not yet published a fix version, no patched-image rebuild is available at this time. HarborGuard re-checks the Oracle and NVD advisory feeds on every ingest cycle and will trigger a rebuild and, for customers with auto-remediation enabled, a regression run and a PR opened against affected workloads, as soon as an upstream fix is released. In the meantime, compensating controls to consider include network-policy rules that restrict HTTP access to the Cost Planning component to only required internal service accounts, egress filtering to limit lateral movement from a compromised instance, and feature-flag or access-control review to ensure no accounts hold unnecessary low-privileged HTTP access to the affected endpoint. Customers should monitor HarborGuard advisory tracking for this CVE and review Oracle's Critical Patch Update schedule for an expected fix date.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Cost Management
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References