CVE-2026-46967: Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization)
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An authorization bypass vulnerability affects the Authorization component of Oracle Public Sector Financials (International), part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is reachable over the network via HTTP and requires only a low-privileged account, with no victim interaction needed. Successful exploitation gives an attacker full control over the affected instance, including read, write, and denial-of-service capabilities across all data handled by the application. No fix version has been published by Oracle; HarborGuard is tracking the advisory for patch availability.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Oracle E-Business Suite components.
AvailableHarborGuard scores this finding at CVSS 8.8 (High) and weights it against each environment's compliance policy to prioritize routing; affected-image alerts are sent to the appropriate team inbox within each customer organization automatically.
AvailableBecause Oracle has not yet published a fix version, HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available the moment an upstream fix is released. In the meantime, customers can apply compensating controls through HarborGuard's network-policy recommendations to restrict HTTP access to affected deployments.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle Public Sector Financials service over the network via HTTP; no local or physical access is required.
- AuthenticationRequired
The attacker must hold a valid low-privilege account on the application; unauthenticated access is not sufficient to trigger the vulnerability.
- Victim interactionNot required
No user action or social engineering is needed; the attacker can exploit the flaw directly without any victim participation.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.
Blast Radius
- A successful attacker reads all data held by the Oracle Public Sector Financials instance, including financial records, budget data, and user credentials.
- The attacker writes or modifies persisted financial records and configuration data, enabling fraud or corruption of public-sector accounting information.
- The attacker crashes or degrades the Oracle Public Sector Financials service, causing a denial of service for all users of the affected deployment.
- Full application takeover means the attacker can pivot to other systems reachable from the compromised E-Business Suite host.
How HarborGuard Handles This
Available on HarborGuard: because Oracle has not yet released a patched version, HarborGuard continuously monitors the advisory and will surface a patched-image rebuild the moment an upstream fix is published, with auto-remediation customers receiving an automated rebuild, regression-test run, and PR opened against affected workloads at that point. Until a patch is available, HarborGuard can surface network-policy isolation recommendations to restrict inbound HTTP access to affected images, limiting exposure to hosts and accounts that genuinely require access. Customers should review which service accounts hold low-privilege credentials to the affected application and consider tightening role assignments as a compensating control. HarborGuard will continue re-evaluating this advisory on every ingest cycle and will notify affected environments as soon as Oracle publishes a fix.
- Oracle Corporation / Oracle Public Sector Financials (International)≤ 12.2.15
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H