Oracle Payments Bug Can Leak the Keys Behind It

Oracle Payments is exposed to more than a file leak here. A single unauthenticated request can make Oracle’s own code read server files, so an attacker who reaches the Payments file-transmission path may walk away with configuration data, database credentials, encryption keys, or payment API keys. Defused says it saw the first in-the-wild exploitation of CVE-2026-46817 on 27 June, about six weeks after Oracle’s May patch and before any public proof of concept. The activity was single-source and targeted, not broad scanning, and it hit Oracle E-Business Suite Payments honeypots running versions 12.2.3 through 12.2.15. The risk is bigger than the bug itself. If an internet-facing EBS Payments instance was left unpatched, the problem may already have moved past the web tier into the secrets that let attackers reach databases and payment integrations.

Part of the PlainSec briefing for 2026-07-01

Sources