Description
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Cost Maintenance module of Oracle Cost Management, a component of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are affected. The flaw allows a low‑privileged attacker who can reach the application over HTTP to compromise Oracle Cost Management, resulting in full takeover of the service. The weakness is an improper access control (CWE‑284) that undermines confidentiality, integrity, and availability of cost data.

Affected Systems

Oracle Cost Management within Oracle E‑Business Suite, specifically versions 12.2.3 to 12.2.15. The issue is confined to the Cost Maintenance component, and only the supported releases in that range are vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 7.5 indicates a high severity impact. An EPSS score of less than 1% suggests a low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a low‑privileged attacker with network access to the HTTP interface to compromise the application.

Generated by OpenCVE AI on August 3, 2026 at 00:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict HTTP access to the Cost Management web service to authorized administrators or via a secure VPN or dedicated network segment.
  • Enforce strict authentication and least‑privilege for all HTTP endpoints of the Cost Maintenance component, and monitor logs for anomalous activity.
  • Monitor Oracle’s security advisories for an official patch or update, and apply it when released.

Generated by OpenCVE AI on August 3, 2026 at 00:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Control Flaw Allows Full Compromise of Oracle Cost Management

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Cost Management Allows Full Compromise

Mon, 27 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Cost Management Allows Full Compromise

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Maintenance). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle cost Management
CPEs cpe:2.3:a:oracle:cost_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle cost Management
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Cost Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:18:32.107Z

Reserved: 2026-05-18T15:55:10.312Z

Link: CVE-2026-46941

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:48.737Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:15:17Z

Weaknesses