HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46957Published Modified CNA oracle

CVE-2026-46957: Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in takeover of Oracle iSupplier Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An authentication-bypass-level takeover vulnerability exists in the Internal Operations component of Oracle iSupplier Portal, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is reachable over the network via HTTP and requires a low-privileged account, but exploitation is difficult due to high attack complexity conditions that must be met. Successful exploitation gives an attacker full control over the iSupplier Portal instance, affecting confidentiality, integrity, and availability. No fix version has been published by Oracle; HarborGuard tracks this advisory and will make a patched-image rebuild available the moment upstream ships a fix.

HarborGuard Coverage

Detection

Detection for CVE-2026-46957 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against customer images, including custom-built images derived from Oracle E-Business Suite base layers. Any image running an affected iSupplier Portal version (12.2.3 through 12.2.15) is flagged automatically at scan time.

Available
Triage

HarborGuard scores this CVE at 7.5 HIGH using the published CVSS v3.1 vector and is capable of weighting that score against each customer environment's compliance policy to reflect actual exposure. Triage results are routed to the appropriate team inbox within each customer organization based on configured ownership and severity thresholds.

Available
Patch

Because no fix version has been published by Oracle, no patched-image rebuild is currently available. HarborGuard re-evaluates this advisory on every ingest cycle and will make a patched-image rebuild available, with auto-remediation customers receiving a rebuild plus regression run and a PR opened against affected workloads, as soon as Oracle publishes a resolution.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the iSupplier Portal service over the network via HTTP; there is no local or physical access requirement.

  • AuthenticationRequired

    A low-privileged account on the iSupplier Portal is sufficient; no administrator or elevated privileges are needed, but some valid credential is required.

  • Victim interactionNot required

    No user interaction is needed; the attacker can execute the attack entirely without any victim taking an action.

  • Attack complexityDetail

    Attack complexity is rated High, meaning the attacker must engineer specific conditions such as race conditions, precise timing, or particular environmental states before the exploit will succeed reliably.

Blast Radius

  • A successful attacker reads all data accessible to the iSupplier Portal, including supplier records, purchase orders, and internal procurement data.
  • A successful attacker modifies or deletes persisted procurement and supplier records within the portal.
  • A successful attacker crashes or destabilizes the iSupplier Portal service, making it unavailable to internal and supplier users.
  • Combined control over confidentiality, integrity, and availability constitutes a full takeover of the affected iSupplier Portal instance.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46957, no patched-image rebuild is queued. HarborGuard monitors the Oracle advisory on every ingest cycle and will trigger the rebuild-and-PR flow the moment a fix version is released; for customers with auto-remediation enabled, that means a rebuilt image, a regression-test run, and a PR opened against affected workloads with no manual intervention required. In the interim, compensating controls worth considering include network-policy rules that restrict HTTP access to iSupplier Portal endpoints to known, authorized source ranges; egress filtering to limit lateral movement if the portal is compromised; and review of which accounts hold the low-privileged access level sufficient to attempt exploitation, with a view to tightening that population. Where compliance policy permits, HarborGuard can surface these compensating-control recommendations directly in the triage ticket routed to the responsible team.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle iSupplier Portal
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
References