CVE-2026-46961: Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An unspecified vulnerability in the Internal Operations component of Oracle Project Portfolio Analysis (part of Oracle E-Business Suite, versions 12.2.3 through 12.2.15) allows a low-privileged attacker to reach the product over HTTP and exploit it without any special conditions. The attacker needs only a valid low-privilege account and network access to the service. Successful exploitation results in full takeover of the affected instance, with complete loss of confidentiality, integrity, and availability. HarborGuard is tracking this advisory as no fix version has been published yet, and will make a patched rebuild available the moment Oracle releases one.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against container images in customer registries and CI/CD pipelines, including custom-built images that package Oracle E-Business Suite components.
AvailableHarborGuard is capable of scoring this CVE at its published CVSS 3.1 rating of 8.8 (High) and weighting it against each environment's compliance policy to route actionable findings to the appropriate team inbox inside each customer organization.
AvailableBecause no fix version has been published by Oracle, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available immediately once an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression run, and PR against affected workloads will be triggered automatically at that point.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle Project Portfolio Analysis service over the network via HTTP; there is no local or physical access requirement.
- AuthenticationRequired
A low-privilege account on the target system is sufficient; no administrative or elevated credentials are needed.
- Victim interactionNot required
No user interaction is required; the attacker can exploit this vulnerability without involving another person.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and imposes no special race conditions, memory-layout dependencies, or other environmental prerequisites.
Blast Radius
- A successful attacker reads all data stored in the Oracle Project Portfolio Analysis instance, including project financials, resource allocations, and any credentials or session tokens held by the application.
- The attacker can modify or delete persisted project records, budgets, and operational data, corrupting the integrity of portfolio reporting.
- The attacker can crash or render the Oracle Project Portfolio Analysis service fully unavailable, disrupting project management and reporting workflows.
- Because the CVSS descriptor references full application takeover, the attacker gains effective control over the Internal Operations component and can pivot to interact with other integrated E-Business Suite modules.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46961, HarborGuard continuously re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle ships a remediated version. For customers with auto-remediation enabled, that rebuild will immediately trigger a regression test run and open a PR against affected workloads. In the interim, compensating controls worth evaluating include network-policy rules that restrict HTTP access to the Oracle Project Portfolio Analysis service to known, authorized source IP ranges; egress filtering to limit the application's outbound reach in case of compromise; and audit-log review for unexpected low-privilege account activity against the Internal Operations component. HarborGuard will surface updated findings automatically as the advisory status changes.
- Oracle Corporation / Oracle Project Portfolio Analysis≤ 12.2.15
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H