Description
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-06-16
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Cost Management, specifically the Cost Planning component, contains a flaw that allows a low‑privileged attacker with network access via HTTP to compromise the application and gain full control. Successful exploitation results in the attacker taking over the entire Cost Management service, thereby undermining confidentiality, integrity, and availability of the system.

Affected Systems

The vulnerability affects Oracle E‑Business Suite Oracle Cost Management versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 indicates a high‑severity flaw. The EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and the issue is not listed within the CISA KEV catalog. The likely attack vector is a network‑based HTTP request, requiring only a low‑privileged account and no user interaction. The condition is that the attacker can reach the Cost Planning service over HTTP and use the flawed privilege controls to take over the system.

Generated by OpenCVE AI on June 17, 2026 at 18:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch for CVE‑2026‑46929 to supported versions.
  • Upgrade to a later release of Oracle Cost Management that supersedes version 12.2.15.
  • Restrict HTTP access to the Cost Management servers to trusted networks and enforce strict role‑based access controls so that low‑privileged accounts cannot invoke privileged functions.
  • Monitor application logs for anomalous activity and perform regular vulnerability scans on the affected component.

Generated by OpenCVE AI on June 17, 2026 at 18:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle cost Management
CPEs cpe:2.3:a:oracle:cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle cost Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Cost Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T14:17:01.528Z

Reserved: 2026-05-18T15:55:10.312Z

Link: CVE-2026-46929

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T03:15:02Z

Weaknesses

No weakness.