CVE-2026-46949: Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Outbound Telephony accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Metrics
- CVSS v3.1
- 9.1
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is an authentication bypass and unauthorized data access vulnerability in the Internal Operations component of Oracle Advanced Outbound Telephony, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is reachable over the network via HTTP with no authentication required and no user interaction needed, making it trivially exploitable from the internet or any network path to the service. Successful exploitation gives an attacker full read access to all data held by the component and the ability to create, modify, or delete critical records. HarborGuard tracks this advisory for patch availability and will make a patched-image rebuild available the moment Oracle publishes a fix.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images layering Oracle E-Business Suite components.
AvailableHarborGuard scores this CVE at CVSS 9.1 (Critical) and surfaces it accordingly in each customer organization's triage queue, weighted against that environment's compliance policy; routing rules direct the finding to the team or inbox responsible for Oracle EBS workloads.
AvailableNo fix version has been published by Oracle for this CVE. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released; for customers with auto-remediation enabled, the rebuild, regression run, and PR against affected workloads will be triggered without manual intervention.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle Advanced Outbound Telephony service over the network via HTTP; any internet-exposed or internally network-accessible deployment is in scope.
- AuthenticationNot required
No account or credential of any kind is needed; the attacker sends unauthenticated HTTP requests directly to the vulnerable component.
- Victim interactionNot required
The exploit is fully server-side and requires no action from any user or administrator to succeed.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and imposes no special conditions such as race windows or specific memory layout requirements.
Blast Radius
- Reads all data accessible to the Oracle Advanced Outbound Telephony component, including call campaign records, agent assignments, and any customer contact data stored within the application.
- Creates, modifies, or deletes critical data rows within the component, allowing an attacker to manipulate outbound call campaigns, falsify records, or destroy operational data.
- Access extends to all data the component can reach within the E-Business Suite schema, not just a subset, due to the High Integrity and High Confidentiality ratings.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46949, the primary actions are detection, isolation, and monitoring. HarborGuard continuously re-evaluates the advisory on each ingest cycle and will trigger a patched-image rebuild the moment Oracle ships a remediated version; for customers with auto-remediation enabled, this means zero manual steps between upstream publication and a PR opened against affected workloads. In the interim, customers are advised to apply network-policy controls that restrict HTTP access to the Internal Operations endpoint to known, trusted source IP ranges; egress filtering at the container or pod level can further limit lateral movement if the component is compromised. Where the Internal Operations functionality is not actively used, feature-flag or application-layer gating can reduce the exposed attack surface until Oracle releases an official patch.
- Oracle Corporation / Oracle Advanced Outbound Telephony≤ 12.2.15
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N