Description
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle Payments’ File Transmission component allows attackers to send unauthenticated HTTP requests that fully compromise the system. The flaw provides complete control over confidentiality, integrity, and availability, enabling a remote attacker to take over Oracle Payments. The weakness is identified as CWE-306, representing insecure authentication. The CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H confirms that the vulnerability is easily exploitable without any user interaction.

Affected Systems

Oracle Payments in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. All deployments of this product in those releases remain vulnerable until an official patch is applied.

Risk and Exploitability

The CVSS Base Score of 9.8 places this flaw in the critical severity range. The EPSS score is less than 1%, indicating an extremely low but nonzero probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is through unauthenticated HTTP requests to the File Transmission component, as inferred from the description of network access via HTTP to compromise Oracle Payments.

Generated by OpenCVE AI on August 21, 2026 at 15:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch referenced in the official Oracle Security Advisory (https://www.oracle.com/security-alerts/cspuaug2026.html).
  • Restrict incoming HTTP traffic to the Oracle Payments endpoint to trusted hosts or IP ranges using firewall or security group rules to reduce the attack surface.
  • Enable detailed logging for the File Transmission component and enforce strict input validation and access controls to detect and mitigate suspicious activity.

Generated by OpenCVE AI on August 21, 2026 at 15:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Title Oracle Payments Unauthenticated File Transmission Vulnerability Allows Remote Takeover

Thu, 20 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle payments
CPEs cpe:2.3:a:oracle:payments:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payments
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-20T19:51:11.432Z

Reserved: 2026-07-08T15:51:55.590Z

Link: CVE-2026-60782

cve-icon Vulnrichment

Updated: 2026-08-20T19:50:51.593Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:16:43.237

Modified: 2026-08-26T17:44:09.697

Link: CVE-2026-60782

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T15:45:18Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function