# CVE-2026-46817: Unauthenticated Arbitrary File Read in Oracle E-Business Suite Payments File Transmission Exploited Before Public PoC

> A critical (CVSS 9.8) unauthenticated arbitrary file read vulnerability in Oracle E-Business Suite Payments' File Transmission component (versions 12.2.3-12.2.15) was exploited in the wild beginning June 27, 2026, roughly six weeks after Oracle's May 2026 Critical Patch Update and before any public exploit code existed. Defused researchers observed six targeted requests from a single source against the /OA_HTML/ibytransmit endpoint, and Shadowserver subsequently identified ~950 internet-exposed EBS instances, mostly in the United States.

- **Published:** 2026-07-02T00:00:00Z
- **Last reviewed:** 2026-07-11T07:51:46.590Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1089
- **ID:** TL-2026-1089
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 20 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-46817

## Description

CVE-2026-46817 is a critical, remotely exploitable vulnerability in the File Transmission component of Oracle Payments within Oracle E-Business Suite (EBS), affecting versions 12.2.3 through 12.2.15. Oracle classifies the flaw as resulting from improper privilege management, improper authentication, and missing authentication for a critical function (CWE-306, CWE-287). The vulnerable code path is the /OA_HTML/ibytransmit endpoint, which accepts unauthenticated HTTP POST requests carrying XML payloads. By crafting a malicious POST request to this endpoint, an attacker can redirect an internal Oracle Java function to read arbitrary files from the underlying server filesystem without any credentials, session token, or user interaction -- demonstrated exploitation attempts targeted files such as /etc/passwd, with the broader risk extending to EBS configuration files that may contain database credentials, encryption keys, and payment-processor API keys. Because the File Transmission component sits inside Oracle Payments, Oracle assesses that successful exploitation can lead to takeover of the Oracle Payments module, and by extension exposure of financial transaction data processed by the ERP suite.

Oracle patched the vulnerability in its May 2026 Critical Patch Update (released approximately May 28, 2026). Threat intelligence firm Defused first detected in-the-wild exploitation beginning June 27, 2026 -- roughly six weeks after the patch shipped and notably before any public proof-of-concept or exploit write-up had been released. Defused characterized the observed activity as narrow and deliberate: just six exploitation attempts from a single source, using what appeared to be functional, working exploit code rather than broad opportunistic scanning. This pattern -- a small number of precise requests using pre-PoC exploit code -- strongly suggests the actor either reverse-engineered Oracle's patch (n-day patch-diffing) to derive the vulnerability and build a working exploit within six weeks, or obtained/purchased a private exploit prior to public disclosure. Both possibilities point to above-average attacker sophistication and a deliberate, high-value targeting posture rather than commodity mass exploitation.

Following public reporting of exploitation (Help Net Security, June 30, 2026; The Register, July 2, 2026), the Shadowserver Foundation applied an improved EBS fingerprinting methodology -- developed in collaboration with Validin LLC -- and identified approximately 950 Oracle E-Business Suite instances still reachable from the public internet, the majority located in the United States. Shadowserver cautioned that this figure reflects internet-facing visibility only, not confirmed vulnerability status, since some instances may already be patched. Nonetheless, the exposure count establishes a meaningful attack surface for follow-on exploitation once public PoC code circulates.

This incident continues a pattern of aggressive targeting of Oracle E-Business Suite by threat actors throughout 2025-2026, most notably the Cl0p ransomware group's large-scale exploitation of a separate EBS vulnerability (CVE-2025-61882) disclosed in October 2025, which affected 100+ organizations, and a June 2026 PeopleSoft zero-day claimed by the ShinyHunters extortion group against 100+ additional organizations. The recurrence of pre-disclosure/pre-PoC exploitation against Oracle's ERP product line indicates sustained interest from data-theft and extortion-motivated actors in Oracle enterprise application vulnerabilities, and suggests some actors maintain the capability to weaponize Oracle CPU patches faster than the defender community can develop detections.

## MITRE ATT&CK

- T1595 Active Scanning
- T1588 Obtain Capabilities
- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1211 Exploitation for Stealth
- T1552 Unsecured Credentials
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1005 Data from Local System
- T1567 Exfiltration Over Web Service
- T1531 Account Access Removal
- T1588.006 Obtain Capabilities: Vulnerabilities
- T1068 Exploitation for Privilege Escalation
- T1552.001 Unsecured Credentials: Credentials In Files
- T1213 Data from Information Repositories
- T1078 Valid Accounts
- T1590 Gather Victim Network Information
- T1587 Develop Capabilities
- T1602 Data from Configuration Repository
- T1071 Application Layer Protocol
- T1565 Data Manipulation

## Sources

- [Oracle E-Business Suite was under attack via critical flaw before the public exploit code was even released](https://www.theregister.com/cyber-crime/2026/07/02/oracle-e-business-suite-was-under-attack-via-critical-flaw-before-the-public-exploit-code-was-even-released/5265710)
- [Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)](https://www.helpnetsecurity.com/2026/06/30/oracle-payments-cve-2026-46817-exploitation/)
- [Hackers now exploit critical Oracle E-Business flaw in attacks](https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-flaw-now-exploited-in-attacks/)
- [Oracle EBS Flaw CVE-2026-46817 Exposes Oracle Payments to Takeover](https://socradar.io/blog/cve-2026-46817-oracle-payments-takeover/)
- [Exploitation of Recent Oracle E-Business Suite Vulnerability Begins](https://www.securityweek.com/exploitation-of-recent-oracle-e-business-suite-vulnerability-begins/)
- [Active Exploitation Alert: Critical Oracle E-Business Suite CVE-2026-46817 Vulnerability Targeting Oracle Payments Module](https://www.rescana.com/post/active-exploitation-alert-critical-oracle-e-business-suite-cve-2026-46817-vulnerability-targeting-oracle-payments-module)
- [950 Oracle E-Business Suite Instances Exposed as Critical Flaw Faces Exploitation](https://cyberpress.org/950-oracle-e-business-suite-exposed/)
- [Oracle E-Business Suite Flaw Under Active Attack, 950 Systems Exposed](https://securityaffairs.com/194599/security/oracle-e-business-suite-flaw-under-active-attack-950-systems-exposed.html)
- [Over 900 Oracle E-Business instances exposed to ongoing attacks](https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-instances-exposed-to-ongoing-attacks/)
- [Critical Oracle E-Business Suite Flaw Exploited for Unauthenticated Takeover](https://www.mallory.ai/stories/019f145d-1ac9-7852-8dbe-e175dc5ddeb6)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1089
