A critical vulnerability in the File Transmission component of Oracle Payments (Oracle E-Business Suite versions 12.2.3–12.2.15) allows an unauthenticated remote attacker to fully compromise the affected system via HTTP, with no user interaction or prior privileges required. Successful exploitation can result in complete takeover of Oracle Payments, impacting confidentiality, integrity, and availability.
Oracle EBS is self-hosted enterprise software, meaning the attack surface is directly determined by how organizations expose the application on their own infrastructure. The low attack complexity and absence of any authentication barrier make this vulnerability particularly dangerous for internet- or network-exposed deployments.
Organizations running affected versions should apply Oracle’s Critical Patch Update (CPU) for May 2026 immediately and review network access controls to restrict exposure of Oracle EBS HTTP endpoints to trusted sources only.

