What is CVE-2026-46954?
An easily exploitable vulnerability has been identified in the Oracle Human Resources module (Data Removal Tool component) of Oracle E-Business Suite, allowing a high-privileged attacker with network access via HTTP to compromise the system. Affected versions range from 12.2.3 to 12.2.15. It is strongly recommended to apply the necessary patches provided by Oracle immediately.
Azərbaycanca: Oracle E-Business Suite-in İnsan Resursları modulunda (Data Removal Tool komponenti) yüksək imtiyazlı şəbəkə istifadəçisi tərəfindən HTTP vasitəsilə asanlıqla istismar edilə bilən təhlükəsizlik boşluğu aşkarlanıb. 12.2.3-dən 12.2.15-ə qədər versiyalar təsirlənir. Təsirə məruz qalan sistemlərin dərhal Oracle-ın tövsiyə etdiyi yamalar ilə yenilənməsi tövsiyə olunur.
Related CVEs
link basis: shared vendor: Oracle
FAQ2
Which module of Oracle E-Business Suite is affected by CVE-2026-46954?
The Human Resources module, specifically the Data Removal Tool component.
What versions of Oracle E-Business Suite are affected by CVE-2026-46954?
Versions from 12.2.3 to 12.2.15 are affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.