CVE-2026-46817

CRITICAL KEV

Oracle Payments 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via File Transmission

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-46817 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 15, 2026. EIP tracks 4 public exploits from researchers including HORKimhab, CIA911, 0xBlackash.

AI-analyzed exploit summary The repository contains no actual exploit code or technical analysis for CVE-2026-46817. Instead, it provides external links to encrypted archives hosted on third-party storage, which is a common tactic for distributing malware or fake exploits under the guise of PoCs.

Description

Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Exploits (4)

github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/46xxx/CVE-2026-46817.md

The repository contains no actual exploit code or technical analysis for CVE-2026-46817. Instead, it provides external links to encrypted archives hosted on third-party storage, which is a common tactic for distributing malware or fake exploits under the guise of PoCs.

Classification
Suspicious 98%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Oracle Payments (Oracle E-Business Suite versions 12.2.3-12.2.15)
No auth needed
Prerequisites: Network access via HTTP to the target Oracle Payments instance
mistral-large-3 · analyzed Jul 02, 2026 Full analysis →
github WORKING POC
by CIA911 · pythonpoc
https://github.com/CIA911/cve-2026-46817_PoC

This repository contains a functional Python-based PoC for CVE-2026-46817, an unauthenticated path traversal vulnerability in Oracle E-Business Suite's File Transmission component. The exploit sends a crafted XML payload to the /OA_HTML/ibytransmit endpoint to read arbitrary files from the server.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Oracle E-Business Suite (12.2.3-12.2.15)
No auth needed
Prerequisites: Python 3.7+ · requests library · network access to target
mistral-large-3 · analyzed Jun 30, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/CVE-2026-46817

The repository lacks actual exploit code or technical details about CVE-2026-46817, instead providing generic setup instructions and a script to download external content. The README is filled with disclaimers and ethical use statements but no substantive vulnerability analysis.

Classification
Suspicious 90%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unspecified
No auth needed
Prerequisites: none specified
mistral-large-3 · analyzed Jun 30, 2026 Full analysis →
github STUB
by 0xBlackash · poc
https://github.com/0xBlackash/CVE-2026-46817

The repository contains only a minimal README with the CVE identifier and no exploit code, technical details, or functional content.

Classification
Stub 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
mistral-large-3 · analyzed Jun 30, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.1331
EPSS Percentile 96.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-07-15
VulnCheck KEV 2026-06-29
ENISA EUVD EUVD-2026-33040
CWE
CWE-269 CWE-287 CWE-306
Status published
Products (2)
oracle/e-business_suite 12.2.3 - 12.2.15
Oracle Corporation/Oracle Payments 12.2.3 - 12.2.15
Published May 28, 2026
KEV Added Jul 15, 2026
Tracked Since May 29, 2026