Oracle Payments is exposed to more than a file leak here. A single unauthenticated request can make Oracle’s own code read server files, so an attacker who reaches the Payments file-transmission path may walk away with configuration data, database credentials, encryption keys, or payment API keys.
Defused says it saw the first in-the-wild exploitation of CVE-2026-46817 on 27 June, about six weeks after Oracle’s May patch and before any public proof of concept. The activity was single-source and targeted, not broad scanning, and it hit Oracle E-Business Suite Payments honeypots running versions 12.2.3 through 12.2.15.
The risk is bigger than the bug itself. If an internet-facing EBS Payments instance was left unpatched, the problem may already have moved past the web tier into the secrets that let attackers reach databases and payment integrations.