CVE-2026-46940: High severity Oracle Oracle Cost Management vulnerability
Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle E-Business Suite - Oracle Cost Management (Cost Planning)to a version that resolves this vulnerability.Fixed in 12.2.3-12.2.15 - Compensating control
Restrict network access to Oracle Cost Management over HTTP so low-privileged remote attackers cannot reach the affected component (Cost Planning).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46940?
The severity of CVE-2026-46940 is high with a CVSS score of 8.8.
How do I fix CVE-2026-46940?
To fix CVE-2026-46940, apply the latest security patches provided by Oracle for the affected versions of Oracle Cost Management.
What products are affected by CVE-2026-46940?
CVE-2026-46940 affects the Oracle Cost Management product within the Oracle E-Business Suite for versions 12.2.3 to 12.2.15.
What type of vulnerability is CVE-2026-46940?
CVE-2026-46940 is an easily exploitable vulnerability that allows a low privileged attacker with network access to compromise Oracle Cost Management.
What impact does CVE-2026-46940 have on data confidentiality?
CVE-2026-46940 can lead to a high impact on confidentiality, integrity, and availability of the affected systems.