CVE-2026-46837
8.8Oracle · Flow Manufacturing
A security vulnerability in Oracle Flow Manufacturing allows a low-privileged authenticated attacker with network access to compromise the system via SQL injection.
Executive summary
A critical SQL injection vulnerability in Oracle Flow Manufacturing could allow an authenticated attacker to achieve full system takeover.
Vulnerability
This is an easily exploitable vulnerability that allows a low-privileged attacker with network access to execute malicious SQL queries, leading to full system compromise. The vulnerability resides within the Security component of the product.
Business impact
With a CVSS score of 8.8, this vulnerability represents a severe threat to the Oracle E-Business Suite environment. Successful exploitation grants an attacker full control over the application, potentially leading to massive data breaches, unauthorized financial transactions, and significant operational disruption.
Remediation
Immediate Action: Apply the relevant Oracle Critical Patch Update (CPU) for the May 2026 cycle immediately to remediate the vulnerability.
Proactive Monitoring: Review database audit logs for anomalous SQL queries or unauthorized access patterns initiated by low-privileged service accounts.
Compensating Controls: Restrict network access to the E-Business Suite management interfaces and ensure that database activity is monitored for signs of unauthorized injection attempts.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Due to the potential for total system takeover, immediate application of Oracle’s official security patches is mandatory. Security teams should verify that the patch is applied across all instances of the E-Business Suite to prevent unauthorized access.