Threat reportVulnerabilityTL-2026-1089

CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoC

criticalACTIVE

CVE-2026-46817 (TL-2026-1089) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-07-02 and last reviewed 2026-07-11. It has no confirmed attribution, affects Oracle E-Business Suite - Oracle Payments (File Transmission, references 1 CVE (CVE-2026-46817), maps to 21 MITRE ATT&CK techniques (T1005, T1068, T1071), and is covered by 9 detection rules and 20 indicators of compromise.

CVSS
9.8/10Critical
CVEs
1Referenced vulnerabilities
Techniques
21MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
20Indicators of compromise

Key facts for TL-2026-1089

Threat ID
TL-2026-1089
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
enterprise-erp-users, finance, manufacturing, retail, government administration, health
Target regions
North America, Global
Detection rules
9
Indicators of compromise
20
Updates
2026-07-11 · revalidated 1× · latest source

How CVE-2026-46817 works

A critical (CVSS 9.8) unauthenticated arbitrary file read vulnerability in Oracle E-Business Suite Payments' File Transmission component (versions 12.2.3-12.2.15) was exploited in the wild beginning June 27, 2026, roughly six weeks after Oracle's May 2026 Critical Patch Update and before any public exploit code existed. Defused researchers observed six targeted requests from a single source against the /OA_HTML/ibytransmit endpoint, and Shadowserver subsequently identified ~950 internet-exposed EBS instances, mostly in the United States.

CVE-2026-46817 is a critical, remotely exploitable vulnerability in the File Transmission component of Oracle Payments within Oracle E-Business Suite (EBS), affecting versions 12.2.3 through 12.2.15. Oracle classifies the flaw as resulting from improper privilege management, improper authentication, and missing authentication for a critical function (CWE-306, CWE-287). The vulnerable code path is the /OA_HTML/ibytransmit endpoint, which accepts unauthenticated HTTP POST requests carrying XML payloads. By crafting a malicious POST request to this endpoint, an attacker can redirect an internal Oracle Java function to read arbitrary files from the underlying server filesystem without any credentials, session token, or user interaction -- demonstrated exploitation attempts targeted files such as /etc/passwd, with the broader risk extending to EBS configuration files that may contain database credentials, encryption keys, and payment-processor API keys. Because the File Transmission component sits inside Oracle Payments, Oracle assesses that successful exploitation can lead to takeover of the Oracle Payments module, and by extension exposure of financial transaction data processed by the ERP suite.

Oracle patched the vulnerability in its May 2026 Critical Patch Update (released approximately May 28, 2026). Threat intelligence firm Defused first detected in-the-wild exploitation beginning June 27, 2026 -- roughly six weeks after the patch shipped and notably before any public proof-of-concept or exploit write-up had been released. Defused characterized the observed activity as narrow and deliberate: just six exploitation attempts from a single source, using what appeared to be functional, working exploit code rather than broad opportunistic scanning. This pattern -- a small number of precise requests using pre-PoC exploit code -- strongly suggests the actor either reverse-engineered Oracle's patch (n-day patch-diffing) to derive the vulnerability and build a working exploit within six weeks, or obtained/purchased a private exploit prior to public disclosure. Both possibilities point to above-average attacker sophistication and a deliberate, high-value targeting posture rather than commodity mass exploitation.

Following public reporting of exploitation (Help Net Security, June 30, 2026; The Register, July 2, 2026), the Shadowserver Foundation applied an improved EBS fingerprinting methodology -- developed in collaboration with Validin LLC -- and identified approximately 950 Oracle E-Business Suite instances still reachable from the public internet, the majority located in the United States. Shadowserver cautioned that this figure reflects internet-facing visibility only, not confirmed vulnerability status, since some instances may already be patched. Nonetheless, the exposure count establishes a meaningful attack surface for follow-on exploitation once public PoC code circulates.

This incident continues a pattern of aggressive targeting of Oracle E-Business Suite by threat actors throughout 2025-2026, most notably the Cl0p ransomware group's large-scale exploitation of a separate EBS vulnerability (CVE-2025-61882) disclosed in October 2025, which affected 100+ organizations, and a June 2026 PeopleSoft zero-day claimed by the ShinyHunters extortion group against 100+ additional organizations. The recurrence of pre-disclosure/pre-PoC exploitation against Oracle's ERP product line indicates sustained interest from data-theft and extortion-motivated actors in Oracle enterprise application vulnerabilities, and suggests some actors maintain the capability to weaponize Oracle CPU patches faster than the defender community can develop detections.

MITRE ATT&CK techniques used in TL-2026-1089

Collection

T1005 Data from Local System; T1213 Data from Information Repositories; T1602 Data from Configuration Repository

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol

Initial Access

T1078 Valid Accounts; T1190 Exploit Public-Facing Application

Discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

Execution

T1203 Exploitation for Client Execution

Defense Evasion

T1211 Exploitation for Stealth

Impact

T1531 Account Access Removal; T1565 Data Manipulation

Credential Access

T1552 Unsecured Credentials; T1552.001 Unsecured Credentials: Credentials In Files

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1587 Develop Capabilities; T1588 Obtain Capabilities; T1588.006 Obtain Capabilities: Vulnerabilities

Reconnaissance

T1590 Gather Victim Network Information; T1595 Active Scanning

Affected products and versions in CVE-2026-46817

  • Oracle — E-Business Suite - Oracle Payments (File Transmission component)
    Vulnerable versions: 12.2.3; 12.2.4; 12.2.5; 12.2.6; 12.2.7; 12.2.8; 12.2.9; 12.2.10; 12.2.11; 12.2.12
    Fixed in: 12.2.x with May 2026 Critical Patch Update applied

Remediation for CVE-2026-46817

Patches

  • Oracle May 2026 Critical Patch Update (CPU) - patches CVE-2026-46817 in Oracle Payments File Transmission component

Immediate actions

  • Apply Oracle's May 2026 Critical Patch Update (CPU) to all Oracle E-Business Suite 12.2.3-12.2.15 instances immediately if not already patched
  • Restrict access to EBS web interfaces (especially /OA_HTML/) to internal networks only; remove direct internet exposure
  • Review web/application server logs for suspicious unauthenticated POST requests to /OA_HTML/ibytransmit dated on or after May 28, 2026
  • Treat any internet-facing, unpatched EBS instance observed after May 28, 2026 as potentially compromised and initiate incident response
  • Rotate database credentials, encryption keys, and payment-processor API keys stored in EBS configuration files if compromise is suspected or confirmed

Workarounds

  • If patching is not immediately possible, block or firewall external access to the /OA_HTML/ibytransmit endpoint
  • Disable or restrict the Oracle Payments File Transmission feature if not in active business use

Longer-term hardening

  • Place Oracle EBS behind a VPN or allowlisted reverse proxy rather than exposing it directly to the internet
  • Implement network segmentation to isolate ERP/payment systems from general internet-facing infrastructure
  • Establish a faster internal patch-validation and deployment cadence for Oracle Critical Patch Updates given demonstrated n-day weaponization speed
  • Deploy file-integrity and anomalous-file-access monitoring on EBS application servers
  • Subscribe to Shadowserver and Defused advisories for early warning of EBS exploitation activity

CVEs associated with CVE-2026-46817

CVE-2026-46817

Weaknesses (CWE) in CVE-2026-46817

CWE-306, CWE-287, CWE-269

Timeline of CVE-2026-46817

  • NVD publishes the CVE-2026-46817 record following Oracle's May 2026 Critical Patch Update, which addressed 77 vulnerabilities in total.
  • Oracle releases the May 2026 Critical Patch Update, which addresses CVE-2026-46817 in the Oracle Payments File Transmission component of E-Business Suite.
  • CISA-ADP updates its enrichment data for CVE-2026-46817 shortly after the NVD publication.
  • Defused researchers first observe in-the-wild exploitation of CVE-2026-46817: six targeted unauthenticated file-read requests against the /OA_HTML/ibytransmit endpoint from a single source, using functional exploit code despite no public PoC existing.
  • Shadowserver records 456 exploitation-pattern attack hits against internet-facing Oracle EBS honeypots/instances, corroborating Defused's initial detection.
  • SecurityWeek, SocRadar, and Rescana publish technical breakdowns detailing the /OA_HTML/ibytransmit endpoint, CWE-306/CWE-287 root cause, and mitigation guidance.
  • Help Net Security and BleepingComputer publish the first public reports of active exploitation of CVE-2026-46817, citing Defused's findings.
  • Shadowserver Foundation, working with Validin LLC on improved fingerprinting, publishes findings identifying approximately 950 internet-exposed Oracle E-Business Suite instances worldwide, mostly in the United States with additional exposure in Europe and Asia.
  • Cyberpress, Security Affairs, and BleepingComputer report on the Shadowserver exposure count, urging administrators to patch and restrict internet access to EBS instances.
  • The Shadowserver Foundation, using an improved EBS fingerprinting method developed with Validin LLC, identifies approximately 950 internet-exposed Oracle E-Business Suite instances, predominantly in the United States.
  • TL-Intel Harness flags CVE-2026-46817 for threat intelligence documentation based on active pre-PoC exploitation against a widely-deployed ERP suite.
  • The Register publishes analysis emphasizing that exploitation preceded any public proof-of-concept release, indicating the attacker reverse-engineered Oracle's patch or possessed a private exploit.
  • Threat-Modeling.com's Vulnerability Intelligence Report catalogs CVE-2026-46817 alongside other actively-exploited flaws in its weekly roundup, reflecting continued industry tracking of the vulnerability.

Update history for TL-2026-1089

Sources cited for CVE-2026-46817

Detection coverage for TL-2026-1089

As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1089 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
20 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats