HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46942Published Modified CNA oracle

CVE-2026-46942: Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Process Planning. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Process Planning. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An authorization or privilege escalation vulnerability affects the Internal Operations component of Oracle Process Manufacturing Process Planning, part of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw is reachable over the network via HTTP and requires only a low-privileged account, with no user interaction needed. Successful exploitation gives an attacker full control over the affected component, impacting confidentiality, integrity, and availability. No fix version has been published by Oracle; HarborGuard is tracking the advisory and will make a patched-image rebuild available the moment upstream ships a fix.

HarborGuard Coverage

Detection

Detection for CVE-2026-46942 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images, including custom-built images that bundle Oracle E-Business Suite components. Any image running an affected version of Oracle Process Manufacturing Process Planning (12.2.3 through 12.2.15) is flagged automatically in registry scans and CI pipeline checks.

Available
Triage

HarborGuard scores this CVE at 8.8 (HIGH) using the published CVSS v3.1 vector and applies each customer org's compliance policy weighting to adjust priority accordingly. Findings are routed to the appropriate team inbox within each customer environment based on ownership rules configured in the HarborGuard policy engine.

Available
Patch

Because no upstream fix version has been published, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle releases a remediated version. In the meantime, customers with auto-remediation enabled will receive compensating-control recommendations such as network-policy isolation and egress filtering for workloads running the affected component.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the affected service over the network via HTTP; there is no requirement for local or physical access.

  • AuthenticationRequired

    Any low-privilege account with network access to the application is sufficient; no administrative credentials are needed.

  • Victim interactionNot required

    No interaction from a victim user is required; the attacker can exploit the flaw entirely on their own.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special conditions, race timing, or environmental factors to succeed.

Blast Radius

  • A successful attacker reads all data accessible to the Oracle Process Manufacturing Process Planning component, including production plans, batch records, and any credentials or tokens stored within the application.
  • The attacker can modify or delete persisted planning data, formula records, and operational configurations within the affected component.
  • The attacker can crash or render the Oracle Process Manufacturing Process Planning service unavailable, disrupting manufacturing operations that depend on it.
  • Combined high impact across confidentiality, integrity, and availability means a successful attack constitutes a full takeover of the affected component.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46942, the platform monitors the advisory on every ingest cycle and will automatically trigger a patched-image rebuild the moment an upstream fix is released. For customers with auto-remediation enabled, that rebuild will be followed by a regression-test run and a PR opened against affected workloads with no manual intervention required. While no patch is available, HarborGuard surfaces compensating-control guidance for affected environments: applying Kubernetes network policies to restrict inbound HTTP access to the affected service to known-good source addresses, enabling egress filtering to limit lateral movement from a compromised pod, and where possible, feature-flag gating or disabling the Internal Operations component if it is not actively needed. All flagged images remain in the HarborGuard findings queue and will be automatically linked to the upstream fix record the moment Oracle publishes one.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Process Manufacturing Process Planning
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References