CVE-2026-46950: High severity Oracle Oracle Advanced Outbound Telephony vulnerability
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle Advanced Outbound Telephony HTTP endpoints to only trusted management IPs using firewall rules or ACLs; block all other inbound HTTP access (especially from the Internet).
- Compensating control
Place the Oracle Advanced Outbound Telephony application behind a web application firewall (WAF) or reverse proxy to inspect and block malicious HTTP requests targeting the application until an official fix is available.
- Compensating control
Apply network segmentation/isolation (VLANs, private subnets) so that only necessary systems and administrators can reach the affected Oracle component over HTTP.
- Operational
If the instance is Internet-facing or otherwise exposed, consider taking the service offline or disabling its HTTP access until a vendor-supplied patch or mitigation is available.
- Operational
Enhance monitoring and logging for the Oracle Advanced Outbound Telephony application: review logs and network traffic for signs of exploitation, and initiate incident response (containment, forensics, recovery) if compromise is suspected.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46950?
The severity of CVE-2026-46950 is rated as high, with a CVSS score of 8.8.
How do I fix CVE-2026-46950?
To fix CVE-2026-46950, update Oracle Advanced Outbound Telephony to a patched version provided by Oracle.
Who is affected by CVE-2026-46950?
CVE-2026-46950 affects users of Oracle E-Business Suite versions 12.2.3 through 12.2.15.
Is CVE-2026-46950 easily exploitable?
Yes, CVE-2026-46950 is considered easily exploitable for a low privileged attacker with network access via HTTP.
What components are affected by CVE-2026-46950?
CVE-2026-46950 specifically affects the Internal Operations component of the Oracle Advanced Outbound Telephony product.