Critical Oracle E-Business Suite Bug Lets Attackers Hijack Enterprise Systems

A critical unauthenticated vulnerability in Oracle E-Business Suite is now being actively exploited in the wild, with honeypot telemetry confirming real-world attack attempts over the weekend of June 27–28, 2026.

The Flaw CVE-2026-46817 is a maximum-severity flaw residing in the File Transmission component of Oracle Payments, a core module within Oracle E-Business Suite (EBS).

The vulnerability carries a CVSS 3.1 Base Score of 9.8, the highest exploitability tier, and affects EBS versions 12.2.3 through 12.2.15.

Critical Oracle E-Business Suite Flaw

The flaw is classified as “easily exploitable,” requiring no authentication, no user interaction, and no prior privileges.

An attacker with network access via HTTP can fully compromise the Oracle Payments system, resulting in complete loss of confidentiality, integrity, and availability the textbook definition of a full system takeover.

Oracle vulnerability exploited (Source: Defused)

Over the weekend of June 27–28, 2026, threat actors were observed actively targeting Oracle E-Business Suite honeypots via POST requests to /OA_HTML/ibytransmit on port 443.

The attacking IP 45.84.137.125, attributed to AS136787 PacketHub S.A. (France), sent crafted XML payloads using the user-agent string ibytransmit-lab-poc/1.0, indicating purpose-built tooling.

The payload revealed an attempted local file read attack targeting /etc/passwd, embedded within a structured <DeliveryRequest> XML body using Oracle’s iPayment transmission protocol.

Despite no public proof-of-concept code existing for this vulnerability, the sophistication of the exploit payload strongly suggests private exploit tooling developed by the threat actor.

Honeypot data from the Shadowserver Foundation spanning May 30 to June 28, 2026, shows attack traffic distributed globally, with North America (193), Asia (181), Europe (53), South America (18), Africa (9), and Oceania (2) all registering hits on the final observation date.

Attack traffic (Source: SHadowserver)
Threat Activity (Source: SHadowserver)

The sustained volume of events above 400 daily indicates a broad, ongoing scanning and exploitation campaign.

Oracle patched CVE-2026-46817 as part of its May 2026 Critical Security Patch Update (CSPU), released on May 28, 2026. The advisory covered 35 unique CVEs across five Oracle product families.

Oracle has strongly urged customers to apply patches immediately and recommends that organizations remain on actively supported EBS versions.

Mitigation

  • Apply Oracle’s May 2026 CSPU patch for all affected EBS instances (versions 12.2.3–12.2.15) immediately
  • Restrict HTTP/HTTPS access to Oracle EBS endpoints to trusted IP ranges and internal networks only
  • Monitor for POST requests to /OA_HTML/ibytransmit with anomalous XML payloads, particularly those referencing CODEX_PULL transmission schemes or file path parameters
  • Block or investigate traffic from 45.84.137.125 and review logs for the ibytransmit-lab-poc user-agent string.
  • Review network perimeter controls to ensure Oracle EBS is not directly exposed to the public internet.

With no previous exploitation history and private exploit tooling already in use, organizations running unpatched Oracle EBS instances face imminent risk of full system compromise. Patching immediately is non-negotiable.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories