HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46950Published Modified CNA oracle

CVE-2026-46950: Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An unspecified vulnerability in the Internal Operations component of Oracle Advanced Outbound Telephony (part of Oracle E-Business Suite, versions 12.2.3 through 12.2.15) allows a low-privileged attacker to reach the service over HTTP and fully compromise the application. No victim interaction is required, and the attack complexity is low, making this straightforward to exploit reliably. Successful exploitation gives the attacker full control over the affected service, covering confidentiality, integrity, and availability. No fix version has been published by Oracle; HarborGuard is tracking the advisory and will make a patched-image rebuild available as soon as an upstream fix is released.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Oracle E-Business Suite components.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the published CVSS v3.1 vector and is capable of weighting that score against each customer organization's compliance policy to route alerts to the appropriate team inbox.

Available
Patch

Because no fix version has been published by Oracle, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment an upstream fix is released. In the interim, HarborGuard surfaces the affected images and supports applying network-policy annotations or egress controls as compensating measures.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle Advanced Outbound Telephony service over the network via HTTP; the application must be network-accessible for exploitation to succeed.

  • AuthenticationRequired

    Any low-privilege account with access to the application is sufficient; no administrative or elevated credentials are needed.

  • Victim interactionNot required

    The attack is fully attacker-driven and requires no action from a logged-in user or administrator.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and imposes no race conditions, special memory layout requirements, or other environmental prerequisites.

Blast Radius

  • A successful attacker reads all data accessible to the Oracle Advanced Outbound Telephony application, including telephony configuration, campaign data, and any stored credentials or session material.
  • The attacker can modify or delete persisted records within the application, including call lists, agent assignments, and operational configuration.
  • The attacker can crash or render the Oracle Advanced Outbound Telephony service unavailable, disrupting outbound calling operations.
  • Full application takeover means the attacker can pivot through the compromised service to reach adjacent E-Business Suite components that trust its internal calls.

How HarborGuard Handles This

Available on HarborGuard: this CVE is matched against customer images continuously as the advisory is re-ingested each cycle. Because Oracle has not yet published a fix for versions 12.2.3 through 12.2.15, no patched-image rebuild is currently available. HarborGuard will generate that rebuild automatically the moment Oracle ships a corrected package. While no patch exists, customers can apply compensating controls through HarborGuard's network-policy suggestion workflow: restricting HTTP access to the Internal Operations component to known trusted source CIDRs, enforcing egress filtering on pods running E-Business Suite components, and flagging the affected images in any compliance gate to block promotion to production. For customers with auto-remediation enabled, a rebuilt image, regression-test run, and a PR opened against affected workloads will be triggered without manual intervention once an upstream fix is available.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Advanced Outbound Telephony
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References