# CVE-2026-46817: Active Exploitation Against ~950 Internet-Exposed Oracle E-Business Suite Payments Instances

> A critical (CVSS 9.8) unauthenticated remote takeover flaw in the File Transmission component of Oracle Payments (Oracle E-Business Suite 12.2.3-12.2.15) is under active in-the-wild exploitation. Honeypot telemetry from Defused captured crafted XML DeliveryRequest payloads against the /OA_HTML/ibytransmit endpoint attempting to read /etc/passwd, while Shadowserver and Validin identified roughly 950 internet-exposed EBS instances via enhanced IP- and domain-based fingerprinting.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-16T11:34:56.708Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1073
- **ID:** TL-2026-1073
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 19 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-46817

## Description

CVE-2026-46817 is an improper privilege management / missing authentication for a critical function vulnerability (CWE-306, CWE-287) in the File Transmission sub-component of the Oracle Payments product within Oracle E-Business Suite (EBS). It affects EBS versions 12.2.3 through 12.2.15. The flaw allows an unauthenticated attacker with network access via HTTP to fully compromise Oracle Payments (confidentiality, integrity, and availability) with low attack complexity and no user interaction, via crafted requests to the iPayment file transmission endpoint /OA_HTML/ibytransmit.

Oracle patched the vulnerability in its May 2026 Critical Security Patch Update (CSPU), released May 28, 2026, with a supplementary June 2026 CSPU released June 16, 2026. On June 27-28, 2026 -- roughly four weeks after the patch and before any public proof-of-concept existed -- threat-intelligence firm Defused observed the first in-the-wild exploitation attempts on its Oracle EBS honeypot infrastructure. The captured traffic consisted of POST requests to /OA_HTML/ibytransmit carrying a crafted XML DeliveryRequest payload using the CODEX_PULL transmission scheme, with the FULL_FILE_PATH parameter set to /etc/passwd -- a classic local file read / path traversal exploitation pattern used to exfiltrate sensitive server files (and potentially database credentials, encryption keys, or payment processor API keys from EBS configuration files). The observed source IP, 45.84.137.125, resolves to AS136787 (PacketHub S.A., France), though researchers assessed the attacker was routing traffic through a VPN/proxy to obscure true origin. Requests used the identifying User-Agent string ibytransmit-lab-poc/1.0 and targeted HTTPS/443.

Defused's broader monitoring recorded 456 exploitation attempts against monitored honeypots in a single 24-hour window (June 28, 2026), distributed globally: North America (193), Asia (181), Europe (53), South America (18), Africa (9), Oceania (2) -- indicating the activity had shifted from a single targeted proof-of-concept probe to broader opportunistic scanning within roughly 24 hours.

Separately, the Shadowserver Foundation, working with Validin LLC, enhanced its Oracle EBS internet-exposure fingerprinting by adding domain-based scanning to its existing IP-based fingerprinting methodology. This identified approximately 950 (reported as 'over 900') internet-accessible Oracle EBS instances globally, more than half based in the United States, representing organizations running finance, supply chain, HR, and back-office systems that are potentially vulnerable to CVE-2026-46817 if unpatched. Shadowserver published its findings via its public dashboard and social channels on July 1, 2026.

This incident follows a pattern of prior critical unauthenticated RCE flaws in Oracle EBS being weaponized rapidly after patch release -- most notably CVE-2025-61882, exploited by the Cl0p ransomware/extortion group in August 2025 for mass data-theft extortion campaigns against EBS customers. While no attribution to a named threat actor or group has been established for CVE-2026-46817 exploitation as of this report, the honeypot-observed activity progressing from a single targeted PoC-style probe to widespread scanning within a day is consistent with either a researcher/red-team validating exploitation feasibility or an early-stage opportunistic threat actor preparing for a larger campaign (potentially including ransomware/extortion operators who have previously targeted this exact product line).

## MITRE ATT&CK

- T1595 Active Scanning
- T1592 Gather Victim Host Information
- T1587 Develop Capabilities
- T1583 Acquire Infrastructure
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1090 Proxy
- T1211 Exploitation for Stealth
- T1552 Unsecured Credentials
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1213 Data from Information Repositories
- T1567 Exfiltration Over Web Service
- T1657 Financial Theft
- T1590 Gather Victim Network Information
- T1588.005 Obtain Capabilities: Exploits
- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1528 Steal Application Access Token
- T1602 Data from Configuration Repository
- T1136.001 Create Account: Local Account
- T1505.003 Server Software Component: Web Shell
- T1531 Account Access Removal
- T1565.001 Data Manipulation: Stored Data Manipulation

## Sources

- [Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild](https://thehackernews.com/2026/06/oracle-e-business-suite-flaw-cve-2026.html)
- [Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)](https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/)
- [Over 900 Oracle E-Business instances exposed to ongoing attacks](https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks/)
- [Attackers actively exploit the Oracle E-Business Suite flaw CVE-2026-46817](https://securityaffairs.com/194463/security/attackers-actively-exploit-the-oracle-e-business-suite-flaw-cve-2026-46817.html)
- [Oracle EBS Flaw CVE-2026-46817 Exposes Oracle Payments to Takeover](https://socradar.io/blog/cve-2026-46817-oracle-payments-takeover/)
- [Critical flaw in Oracle E-Business Suite is under immediate threat](https://www.cybersecuritydive.com/news/critical-flaw-oracle-e-business-suite-threat/824230/)
- [Hackers Actively Exploit CVE-2026-46817 in Oracle E-Business Suite - 456 Attacks Recorded in 24 Hours](https://securebulletin.com/hackers-actively-exploit-cve-2026-46817-in-oracle-e-business-suite-456-attacks-recorded-in-24-hours/)
- [Hackers Exploiting Critical Oracle E-Business Suite Vulnerability Actively in Attacks](https://cybersecuritynews.com/oracle-e-business-flaw-actively-exploited/)
- [900+ Oracle E-Business Suite Instances Exposed on the Internet](https://cybersecuritynews.com/900-oracle-e-business-instances-exposed/)
- [Hackers now exploit critical Oracle E-Business flaw in attacks](https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/)
- [NVD - CVE-2026-46817](https://nvd.nist.gov/vuln/detail/CVE-2026-46817)
- [Oracle Critical Patch Update Advisory - May 2026](https://www.oracle.com/security-alerts/cspumay2026.html)
- [CVE-2026-46817 - active exploitation observed](https://defusedcyber.com/exploited/cve-2026-46817-oracle-e-business-suite)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1073
