HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46962Published Modified CNA oracle

CVE-2026-46962: Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a high-severity vulnerability in the Internal Operations component of Oracle Project Portfolio Analysis, part of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). The flaw is reachable over the network via HTTP and requires only a low-privileged account, with no victim interaction needed. Successful exploitation gives an attacker full control over the affected application, including complete read, write, and availability impact. HarborGuard is tracking the advisory for patch availability, as Oracle has not yet published a fix version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: CVE-2026-46962 is ingested from upstream vulnerability feeds within minutes of publication and matched against customer images, including custom-built images that bundle Oracle E-Business Suite components, in both registry scans and CI pipeline checks.

Available
Triage

HarborGuard is capable of scoring this CVE at its published CVSS 3.1 base score of 8.8 (HIGH) and weighting that score against each customer organization's compliance policy to route the finding to the appropriate team inbox with the correct priority level.

Available
Patch

Because Oracle has not yet published a fix for CVE-2026-46962, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment upstream ships a fix. For customers with auto-remediation enabled, the rebuild, regression test run, and PR against affected workloads will be initiated automatically at that point.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must be able to reach the affected Oracle Project Portfolio Analysis service over the network via HTTP; no physical or local access is necessary.

  • AuthenticationRequired

    Any low-privilege account on the system is sufficient; the attacker does not need administrative or elevated credentials.

  • Victim interactionNot required

    No user interaction is needed; the attacker can carry out the exploit entirely without involving another party.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, special memory layouts, or other variable environmental factors.

Blast Radius

  • A successful attacker reads all data stored in Oracle Project Portfolio Analysis, including project records, financial forecasts, and operational data.
  • A successful attacker writes or modifies persisted project and portfolio records, corrupting planning data or injecting false information.
  • A successful attacker can crash or render the Oracle Project Portfolio Analysis service fully unavailable, disrupting project operations.

How HarborGuard Handles This

Available on HarborGuard: because no upstream fix has been published for CVE-2026-46962, HarborGuard continuously monitors the Oracle advisory on every ingest cycle and will surface a patched-image rebuild the moment Oracle releases a remediated version. In the interim, compensating controls available to customers include applying network-policy isolation to restrict HTTP access to Oracle Project Portfolio Analysis to only authorized internal source ranges, enforcing egress filtering on containers running affected EBS components, and reviewing account provisioning to minimize the number of low-privileged accounts that can reach the Internal Operations component. For customers with auto-remediation enabled, a rebuilt image, regression test run, and PR against affected workloads will be triggered automatically as soon as a fix version is published.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Project Portfolio Analysis
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References