Summary
CVE-2026-46930 is a critical unauthenticated remote access vulnerability affecting Oracle In-Memory Cost Management for Discrete Industries (versions 12.2.12 through 12.2.15), a web-based module of Oracle E-Business Suite. Disclosed as part of Oracle’s June 2026 Critical Security Patch Update, the flaw allows unauthenticated network attackers to gain unauthorized read access to sensitive data as well as unauthorized creation, deletion, or modification of critical data within the affected application, earning a CVSS v3.1 base score of 9.1.
Technical details
- Root cause: Oracle has not publicly disclosed the precise root cause; the vulnerability resides in the Internal Operations component of the module and requires no authentication to trigger.
- Trigger conditions: An attacker with network access to the target system can exploit this vulnerability over HTTPS with low attack complexity and no user interaction required.
- Attack vector: Remote, unauthenticated, via HTTPS (AV:N/AC:L/PR:N/UI:N). No local access, credentials, or victim interaction are necessary.
- Impact: High confidentiality impact — unauthorized read access to all application-accessible data; high integrity impact — unauthorized creation, deletion, or modification of critical data. No availability impact.
Affected software
- Oracle In-Memory Cost Management for Discrete Industries 12.2.12
- Oracle In-Memory Cost Management for Discrete Industries 12.2.13
- Oracle In-Memory Cost Management for Discrete Industries 12.2.14
- Oracle In-Memory Cost Management for Discrete Industries 12.2.15
(All affected versions are components of Oracle E-Business Suite 12.2.x.)
Severity
- CVSS v3.1 Base Score: 9.1 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Mitigation and recommended actions
- Immediate action: Apply the patches provided in the Oracle June 2026 Critical Security Patch Update (CSPU June 2026). Patch availability and installation instructions are documented in My Oracle Support Note KA923 (Oracle E-Business Suite Release 12 Critical Security Patch Update Knowledge Document, June 2026).
- If patching cannot be applied immediately: Restrict network access to Oracle E-Business Suite interfaces at the perimeter. Ensure that Oracle EBS login pages and application endpoints are not exposed directly to the public internet. Apply strict firewall rules to limit access to trusted IP ranges only.
- Oracle strongly recommends customers apply Critical Security Patch Update patches without delay.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

