Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
History

Tue, 04 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Authorization Bypass in Oracle Public Sector Financials (International)

Thu, 30 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title High-Privilege Authorization Bypass in Oracle Public Sector Financials (International)

Wed, 29 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title High‑Privilege Authorization Bypass in Oracle Public Sector Financials (International) Leading to Full System Compromise

Fri, 24 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title High‑Privilege Authorization Bypass in Oracle Public Sector Financials (International) Leading to Full System Compromise

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). While the vulnerability is in Oracle Public Sector Financials (International), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle public Sector Financials
CPEs cpe:2.3:a:oracle:public_sector_financials:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Financials
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published: 2026-07-21T21:32:47.918Z

Updated: 2026-07-23T15:19:04.289Z

Reserved: 2026-05-18T15:55:10.311Z

Link: CVE-2026-46923

cve-icon Vulnrichment

Updated: 2026-07-23T15:14:53.109Z

cve-icon NVD

No data.

cve-icon Redhat

No data.