CVE-2026-46817
CRITICAL KEVOracle Payments 12.2.3-12.2.15 - Unauthenticated Remote Code Execution via File Transmission
Title source: llmExploitation Summary
CVE-2026-46817 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 15, 2026. EIP tracks 4 public exploits from researchers including HORKimhab, CIA911, 0xBlackash.
AI-analyzed exploit summary The repository contains no actual exploit code or technical analysis for CVE-2026-46817. Instead, it provides external links to encrypted archives hosted on third-party storage, which is a common tactic for distributing malware or fake exploits under the guise of PoCs.
Description
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Exploits (4)
The repository contains no actual exploit code or technical analysis for CVE-2026-46817. Instead, it provides external links to encrypted archives hosted on third-party storage, which is a common tactic for distributing malware or fake exploits under the guise of PoCs.
This repository contains a functional Python-based PoC for CVE-2026-46817, an unauthenticated path traversal vulnerability in Oracle E-Business Suite's File Transmission component. The exploit sends a crafted XML payload to the /OA_HTML/ibytransmit endpoint to read arbitrary files from the server.
The repository lacks actual exploit code or technical details about CVE-2026-46817, instead providing generic setup instructions and a script to download external content. The README is filled with disclaimers and ethical use statements but no substantive vulnerability analysis.
The repository contains only a minimal README with the CVE identifier and no exploit code, technical details, or functional content.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H