Description
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Oracle Enterprise Command Center Framework that permits a low‑privileged adversary with simple network connectivity over HTTP to create, delete, or alter data without authentication. The weakness stems from improper access control mechanisms, allowing an attacker to both access and modify sensitive information and to cause a partial denial of service. The impact therefore includes confidentiality loss, integrity violation, and limited availability disruption.

Affected Systems

The affected vendors and products are Oracle Corporation’s Oracle Enterprise Command Center Framework, specifically versions 15 and 16. These releases are part of the Oracle E‑Business Suite Core component.

Risk and Exploitability

The CVSS 3.1 base score of 9.9 classifies the issue as critical, and the EPSS score of less than 1% suggests the likelihood of exploitation is low but non‑zero. The vulnerability is not currently listed in CISA’s KEV catalog. The attack vector is inferred to be remote over the network via HTTP, with low privilege required and no user interaction needed. An attacker can therefore achieve unauthorized data manipulation and partial denial of service when exploiting this flaw.

Generated by OpenCVE AI on June 17, 2026 at 19:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch for Oracle Enterprise Command Center Framework v15 and v16 as published by Oracle
  • If a patch is not yet available, disable external HTTP access to the Command Center Framework until the fix is applied
  • Restrict access to the Command Center Framework to trusted network zones and enforce strict role‑based access controls to mitigate potential privilege escalation

Generated by OpenCVE AI on June 17, 2026 at 19:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).
First Time appeared Oracle
Oracle enterprise Command Center Framework
CPEs cpe:2.3:a:oracle:enterprise_command_center_framework:v15:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_command_center_framework:v16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Command Center Framework
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L'}


Subscriptions

Oracle Enterprise Command Center Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:15:59.149Z

Reserved: 2026-05-18T15:55:10.310Z

Link: CVE-2026-46897

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T04:30:03Z

Weaknesses

No weakness.