HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46971Published Modified CNA oracle

CVE-2026-46971: Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations)

Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HR Intelligence. Successful attacks of this vulnerability can result in takeover of Oracle HR Intelligence. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a high-severity vulnerability in the Internal Operations component of Oracle HR Intelligence, part of Oracle E-Business Suite (versions 12.2.3 through 12.2.15). An attacker with a low-privilege account and network access over HTTP can exploit this flaw, though doing so requires meeting difficult environmental conditions. Successful exploitation results in full takeover of the Oracle HR Intelligence application, affecting confidentiality, integrity, and availability. No fix version has been published yet; HarborGuard is tracking the advisory and will surface a patched-image rebuild the moment upstream releases one.

HarborGuard Coverage

Detection

Detection of CVE-2026-46971 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer container images, including custom-built images that package Oracle E-Business Suite components. Any image containing an affected version of Oracle HR Intelligence (12.2.3 through 12.2.15) is flagged automatically.

Available
Triage

HarborGuard is capable of scoring this CVE at its published CVSS 3.1 base score of 7.5 (HIGH) and weighting it against each environment's compliance policy to surface appropriate urgency. Findings are routed to the relevant team inbox within each customer organization based on image ownership and policy configuration.

Available
Patch

No fix version has been published for this CVE. HarborGuard re-checks the Oracle advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will be initiated without manual intervention once a fix version appears.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle HR Intelligence service over the network via HTTP to deliver the exploit.

  • AuthenticationRequired

    Any low-privilege account on the system is sufficient; anonymous access alone does not enable the attack.

  • Victim interactionNot required

    No user interaction is needed; the attacker can carry out the exploit entirely without involving another person.

  • Attack complexityDetail

    Exploitation is rated high complexity, meaning the attacker must satisfy specific environmental conditions or timing constraints beyond simply sending a request.

Blast Radius

  • A successful attacker reads all data accessible to Oracle HR Intelligence, including employee records, compensation details, and HR operational data.
  • A successful attacker modifies or deletes persisted HR data, including payroll configurations and workforce planning records.
  • A successful attacker crashes or destabilizes the Oracle HR Intelligence service, making it unavailable to HR staff and dependent processes.
  • The combination of full confidentiality, integrity, and availability compromise constitutes a complete application takeover, giving the attacker persistent control over the affected instance.

How HarborGuard Handles This

Available on HarborGuard: because no upstream fix exists for CVE-2026-46971 at this time, HarborGuard monitors the Oracle advisory on every ingest cycle and will trigger a patched-image rebuild and, for customers with auto-remediation enabled, open a patch PR against affected workloads the moment Oracle publishes a fix. In the interim, HarborGuard surfaces this finding with its full CVSS 7.5 HIGH score so security teams can act on compensating controls. Recommended compensating controls include restricting network-policy access to the Oracle HR Intelligence HTTP endpoint to known-good source CIDRs, enforcing egress filtering on containers running the affected component, and requiring multi-factor authentication on all accounts that hold even low-privilege access to the application. Where compliance policy permits, teams can gate the affected Internal Operations feature behind a feature flag or configuration toggle while awaiting the upstream patch.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle HR Intelligence
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
References