CVE-2026-46927

Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Receivables. Successful attacks of this vulnerability can result in takeover of Oracle Receivables. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:receivables:*:*:*:*:*:*:*:*

History

18 Jun 2026, 22:14

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-17 10:54

Updated : 2026-06-18 22:14


NVD link : CVE-2026-46927

Mitre link : CVE-2026-46927

CVE.ORG link : CVE-2026-46927


JSON object : View

Products Affected

oracle

  • receivables
CWE
CWE-284

Improper Access Control

CWE-306

Missing Authentication for Critical Function