{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-46817",
  "revision": 1,
  "title": "Oracle E-Business Suite Payments — unauthenticated takeover",
  "summary": "Oracle Payments in Oracle E-Business Suite 12.2.3 through 12.2.15 (File Transmission component) lets an unauthenticated attacker reach it over the web (HTTP) and take it over completely, because authentication and privilege checks are missing. Actively exploited in the wild.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 9.8,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.13017,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-07-15",
    "prerequisites": "Network access over HTTP to the Oracle Payments component of Oracle E-Business Suite; no credentials or user interaction needed."
  },
  "mitre_attack": [
    "T1190"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Apply Oracle's security alert fixes for E-Business Suite 12.2.3-12.2.15 now; block internet access to Oracle Payments HTTP endpoints and hunt for prior compromise.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-46817",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-46817",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-46817",
      "retrieved_at": "2026-09-22T06:10:25.213Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-46817",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://www.oracle.com/security-alerts/cspumay2026.html"
    }
  ],
  "published_at": "2026-05-28T21:16:31.503Z",
  "issued_at": "2026-09-22T06:10:25.213Z",
  "tags": [
    "oracle",
    "e-business-suite",
    "oracle-payments",
    "missing-authentication",
    "improper-privilege-management",
    "kev"
  ]
}
