Vulnerabilities & Exploits

Oracle Payments Bug Can Leak the Keys Behind It

Oracle Payments is exposed to more than a file leak here. A single unauthenticated request can make Oracle’s own code read server files, so an attacker who reaches the Payments file-transmission path may walk away with configuration data, database credentials, encryption keys, or payment API keys.

Defused says it saw the first in-the-wild exploitation of CVE-2026-46817 on 27 June, about six weeks after Oracle’s May patch and before any public proof of concept. The activity was single-source and targeted, not broad scanning, and it hit Oracle E-Business Suite Payments honeypots running versions 12.2.3 through 12.2.15.

The risk is bigger than the bug itself. If an internet-facing EBS Payments instance was left unpatched, the problem may already have moved past the web tier into the secrets that let attackers reach databases and payment integrations.

7 sources · Jul 10

CVE-2026-46817

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). EPSS 13% (96th percentile).

CISA federal remediation date Jul 18

Timeline

Sources

Part of the PlainSec briefing for 2026-06-29

Every edition of this story: Oracle Payments Bug Can Leak the Keys Behind It

More from today