CVE-2026-46962: Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations)
Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is a high-severity vulnerability in the Internal Operations component of Oracle Project Portfolio Analysis, part of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw is reachable over the network via HTTP and requires only a low-privileged account, with no victim interaction needed. Successful exploitation gives an attacker full control over the affected application, including complete read, write, and availability impact. HarborGuard is tracking the advisory for patch availability, as Oracle has not yet published a fix version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: CVE-2026-46962 is ingested from upstream vulnerability feeds within minutes of publication and matched against customer images, including custom-built images that bundle Oracle E-Business Suite components, in both registry scans and CI pipeline checks.
AvailableHarborGuard is capable of scoring this CVE at its published CVSS 3.1 base score of 8.8 (HIGH) and weighting that score against each customer organization's compliance policy to route the finding to the appropriate team inbox with the correct priority level.
AvailableBecause Oracle has not yet published a fix for CVE-2026-46962, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment upstream ships a fix. For customers with auto-remediation enabled, the rebuild, regression test run, and PR against affected workloads will be initiated automatically at that point.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must be able to reach the affected Oracle Project Portfolio Analysis service over the network via HTTP; no physical or local access is necessary.
- AuthenticationRequired
Any low-privilege account on the system is sufficient; the attacker does not need administrative or elevated credentials.
- Victim interactionNot required
No user interaction is needed; the attacker can carry out the exploit entirely without involving another party.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, special memory layouts, or other variable environmental factors.
Blast Radius
- A successful attacker reads all data stored in Oracle Project Portfolio Analysis, including project records, financial forecasts, and operational data.
- A successful attacker writes or modifies persisted project and portfolio records, corrupting planning data or injecting false information.
- A successful attacker can crash or render the Oracle Project Portfolio Analysis service fully unavailable, disrupting project operations.
How HarborGuard Handles This
Available on HarborGuard: because no upstream fix has been published for CVE-2026-46962, HarborGuard continuously monitors the Oracle advisory on every ingest cycle and will surface a patched-image rebuild the moment Oracle releases a remediated version. In the interim, compensating controls available to customers include applying network-policy isolation to restrict HTTP access to Oracle Project Portfolio Analysis to only authorized internal source ranges, enforcing egress filtering on containers running affected EBS components, and reviewing account provisioning to minimize the number of low-privileged accounts that can reach the Internal Operations component. For customers with auto-remediation enabled, a rebuilt image, regression test run, and PR against affected workloads will be triggered automatically as soon as a fix version is published.
- Oracle Corporation / Oracle Project Portfolio Analysis≤ 12.2.15
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H