A vulnerability has been found in Oracle Project Portfolio Analysis up to 12.2.15 and classified as very critical. This vulnerability affects unknown code of the component Internal Operations. The manipulation leads to privilege escalation. This vulnerability is traded as CVE-2026-46961. It is possible to initiate the attack remotely. There is no exploit available. The affected component should be upgraded.
| Vendor | Product | Versions |
|---|---|---|
| oracle | oracle project portfolio analysis | 12.2.3 |
Downstream vendors/products affected by this vulnerability
| Vendor | Product | Source | Confidence |
|---|---|---|---|
| oracle | e-business | cert_advisory | 90% |
Updated severity to CRITICAL, changed exploit availability to false, and provided a new description with additional details.
Initial creation