HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46951Published Modified CNA oracle

CVE-2026-46951: Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An unspecified vulnerability in the Internal Operations component of Oracle Quality, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15, allows a low-privileged attacker to reach the affected component over HTTP and exploit it without any victim interaction. Successful exploitation results in full takeover of Oracle Quality, giving the attacker complete read, write, and availability control over the affected installation. No fix versions have been published; HarborGuard is tracking the advisory and will surface a patched-image rebuild the moment Oracle releases one.

HarborGuard Coverage

Detection

Detection for CVE-2026-46951 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that package Oracle E-Business Suite components. Any image containing an affected Oracle Quality version in the 12.2.3 to 12.2.15 range is flagged automatically.

Available
Triage

HarborGuard triage is available at a CVSS 3.1 score of 8.8 (HIGH), and that score is weighted against each customer organization's compliance policy to determine urgency and routing. Findings are directed to the appropriate team inbox inside each customer org based on configured ownership rules.

Available
Patch

Because no upstream fix version has been published for this CVE, HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle ships a fix. In the meantime, customers can apply compensating controls through HarborGuard's policy engine, such as network-policy isolation to restrict HTTP access to the Internal Operations component to known-good source ranges.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must be able to reach the Oracle Quality service over the network via HTTP; there is no requirement for local or physical access.

  • AuthenticationRequired

    A low-privilege account is sufficient; the attacker must be authenticated to the application but does not need administrative or elevated privileges.

  • Victim interactionNot required

    No user interaction is needed; the attacker can carry out the exploit entirely without involving another person.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special preconditions, race conditions, or environmental factors to succeed.

Blast Radius

  • A successful attacker reads all data accessible to Oracle Quality, including quality records, configuration data, and any credentials or session material stored within the component.
  • The attacker can modify or delete persisted quality records and application configuration, corrupting data integrity across the affected E-Business Suite installation.
  • The attacker can crash or otherwise disrupt the Oracle Quality service, making it unavailable to legitimate users.
  • Because the CVSS descriptor characterizes the outcome as a full takeover, the attacker gains sustained control over the compromised component, enabling follow-on lateral movement within the E-Business Suite environment.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46951, the recommended posture is a combination of active monitoring and compensating controls. HarborGuard re-evaluates the Oracle advisory on every ingest cycle and will automatically surface a patched-image rebuild and, for customers with auto-remediation enabled, open a PR against affected workloads the moment a fix version is released. While no patch is available, customers can use HarborGuard's policy engine to apply network-policy isolation that restricts inbound HTTP access to the Oracle Quality Internal Operations component to explicitly allowlisted source addresses, reducing the exposed attack surface. Egress filtering rules can also be configured to limit the component's outbound reach in the event of compromise. HarborGuard will send an alert to configured notification channels as soon as upstream patch availability changes.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Quality
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References