Description
Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The feature enabling Oracle Enterprise Command Center Framework to accept HTTPS traffic is improperly protected, allowing an unauthenticated network attacker to fully compromise the system. Successful exploitation can lead to complete takeover, compromising confidentiality, integrity, and availability of the entire framework. The severity is reflected in a CVSS 3.1 base score of 9.8, with the vector indicating no authentication, no user interface, and full confidentiality and integrity impact.

Affected Systems

Oracle Enterprise Command Center Framework, versions 15 and 16, supplied by Oracle Corporation. These versions are listed in the vendor’s product catalogue and are covered by the Oracle security alert for June 2026.

Risk and Exploitability

The risk is high: attackers need only network access to HTTPS to exploit the flaw, with a low effective difficulty (Access Complexity Low) and no defenses to prevent it (Privilege None, User Interaction None). The EPSS score of less than 1 % indicates that, as of this analysis, exploitation activity is expected to be very low, yet the vulnerability is listed as not present in the CISA KEV catalogue. Nonetheless, because the impact is catastrophic and the vector is simple, administrators should treat this as an imminent threat. No additional conditions or prerequisites are stated, so any system with the vulnerable versions exposed to the internet is at risk.

Generated by OpenCVE AI on June 17, 2026 at 19:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Oracle security patch referenced in the June 2026 advisory to remediate the flaw
  • Upgrade Oracle Enterprise Command Center Framework to a non‑vulnerable release (e.g., version 16.2 or later) if a patch is not yet available
  • Block inbound HTTPS traffic to the Enterprise Command Center Framework until the patch or upgrade is applied

Generated by OpenCVE AI on June 17, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle enterprise Command Center Framework
CPEs cpe:2.3:a:oracle:enterprise_command_center_framework:v15:*:*:*:*:*:*:*
cpe:2.3:a:oracle:enterprise_command_center_framework:v16:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle enterprise Command Center Framework
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Enterprise Command Center Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T13:40:44.338Z

Reserved: 2026-05-18T15:55:10.310Z

Link: CVE-2026-46902

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T00:30:15Z

Weaknesses

No weakness.