Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

[KEV] CVE-2026-46817 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2026-46817 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2026-46817 is an improper privilege management vulnerability in Oracle E-Business Suite affecting the Oracle Payments component, exploitable by unauthenticated remote attackers over HTTP.

Technical Detail

The flaw stems from improper privilege management within Oracle Payments, a financial transaction processing component of Oracle E-Business Suite. An unauthenticated attacker with network access can send crafted HTTP requests to trigger the vulnerability without requiring any credentials or prior foothold on the system. Successful exploitation results in full takeover of the Oracle Payments component, which in practice means an attacker can read, modify, or destroy payment data and likely pivot further within the E-Business Suite environment.

Exploitation Status

CISA has confirmed active exploitation in the wild, with this vulnerability added to the Known Exploited Vulnerabilities catalog on July 15, 2026. The exploit is rated as operational, meaning functional exploit code exists and is being actively used in targeted or opportunistic attacks rather than remaining limited to proof-of-concept demonstrations.

Who Is Targeting This

Confirmed (ATTAX-verified): UNC3886, a threat actor of Chinese origin operating with nation-state motivation, has been attributed with high confidence to exploitation of this vulnerability. No additional reported or research-inferred threat actors have been identified at this time.

What To Do

Organizations running Oracle E-Business Suite should apply Oracle's available patch for CVE-2026-46817 immediately. Per CISA's binding operational directive, federal agencies are required to remediate this vulnerability by the deadline associated with the July 15, 2026 KEV listing, which typically allows 14 days from the date of addition. If patching cannot be completed immediately, restrict network access to Oracle E-Business Suite and Oracle Payments interfaces at the perimeter, blocking unauthenticated HTTP access from untrusted networks. Given the confirmed involvement of UNC3886, defenders should review logs for anomalous unauthenticated HTTP requests to Payments endpoints, unexpected privilege changes within E-Business Suite, and lateral movement indicators consistent with nation-state post-exploitation activity. The CVSS score of 0.0 in the current data appears to be a data gap and should not be interpreted as low risk given confirmed active exploitation and full component takeover impact.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →