Description
Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Public Sector Financials (International). While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Public Sector Financials (International) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-05-28
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Low‑privileged users achieving network access through HTTPS can exploit an authorization flaw in Oracle Public Sector Financials (International), leading to unauthorized access to critical or all available data. The flaw can also change the attack scope, potentially affecting other Oracle products. Confidentiality is the primary concern, with no explicit integrity or availability impact described.

Affected Systems

Oracle Public Sector Financials (International) of Oracle E‑Business Suite, versions 12.2.6 through 12.2.15, is the affected product. The vulnerability is confined to this product but may impact other Oracle components due to a scope change.

Risk and Exploitability

The CVSS 3.1 base score of 7.7 reflects a high‑severity vulnerability that does not require user interaction and is easily exploitable by an attacker with low privileges. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Attackers would likely target the HTTPS interface of the application, leveraging the scope change to gain broader access. Given the ease of exploitation and the confidentiality impact, the risk to exposed systems remains significant until mitigated.

Generated by OpenCVE AI on May 29, 2026 at 18:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Public Sector Financials to a version outside the 12.2.6‑12.2.15 range or apply the vendor’s official patch.
  • Restrict HTTPS access to authorized IP ranges and monitor connection attempts to detect exploitation attempts.
  • Enforce least‑privilege accounts and disable any legacy authentication mechanisms that may allow bypass of the authorization controls.

Generated by OpenCVE AI on May 29, 2026 at 18:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 19:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Authorization Bypass Allows Data Exposure in Oracle Public Sector Financials (International)
Weaknesses CWE-284

Fri, 29 May 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 28 May 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Authorization Bypass Allows Data Exposure in Oracle Public Sector Financials (International)
Weaknesses CWE-284

Thu, 28 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Public Sector Financials (International). While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Public Sector Financials (International) accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


Subscriptions

Oracle Public Sector Financials
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-05-29T15:37:43.233Z

Reserved: 2026-05-18T15:55:10.303Z

Link: CVE-2026-46823

cve-icon Vulnrichment

Updated: 2026-05-29T15:37:31.504Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-28T21:16:32.280

Modified: 2026-05-29T16:16:29.590

Link: CVE-2026-46823

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T18:45:05Z

Weaknesses