Sceawere

Vulnerability Detail

CVE-2026-70728UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Autonomous Health Framework Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Autonomous Health Framework
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework. While the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Autonomous Health Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Autonomous Health Framework accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework. While the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Autonomous Health Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Autonomous Health Framework accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-08-18T21:17:25.370Z",
  "pubdate": "2026-08-18T21:17:25.370Z",
  "executiveSummary": "A security vulnerability has been identified in the Oracle Autonomous Health Framework, specifically within the Trace File Analyzer component. This easily exploitable vulnerability allows a low-privileged attacker with network access via HTTP to compromise the affected framework. The flaw carries a CVSS 3.1 Base Score of 8.5, indicating severe potential impact on confidentiality and integrity, and features a scope change that signifies attacks may significantly impact additional products beyond the immediate boundary of the Oracle Autonomous Health Framework.\nSuccessful exploitation of this vulnerability grants unauthorized access to critical data or complete access to all data accessible by the Oracle Autonomous Health Framework. Additionally, it enables unauthorized update, insert, or delete access to a subset of the accessible data. The exploitation requirements are minimal, requiring only low privileges and network accessibility using the HTTP protocol, with no user interaction necessary. Organizations utilizing the affected software versions face significant risk to data confidentiality and integrity, necessitating immediate review and remediation actions based on official vendor advisories.",
  "technicalDetails": "The vulnerability resides within the Trace File Analyzer component of the Oracle Autonomous Health Framework. Affected software versions include 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, and 26.5.2. The flaw is exposed via the network attack vector utilizing the HTTP protocol, allowing remote interaction with the vulnerable service without requiring user interaction.\nThe attack vector requires the adversary to possess low privileges within the system, lowering the barrier to entry for internal threat actors or compromised low-level accounts. Because the vulnerability features a scope change (S:C), successful exploitation extends beyond the security scope of the Oracle Autonomous Health Framework, potentially impacting auxiliary products and underlying infrastructure components associated with the deployment.\nThe attack flow begins when an authenticated attacker with low privileges submits maliciously crafted HTTP requests to the vulnerable Trace File Analyzer endpoint. The underlying component fails to properly validate or sanitize the incoming requests, leading to improper authorization or broken access control enforcement. This allows the attacker to bypass security boundaries and interact with backend functions or data stores intended to be restricted.\nUpon successful exploitation, the payload behavior enables the attacker to achieve unauthorized read access to critical data, culminating in complete access to all data accessible by the Oracle Autonomous Health Framework. Furthermore, the attacker gains unauthorized write capabilities, specifically the ability to execute update, insert, or delete operations on a subset of the framework-accessible data. The impact is strictly isolated to confidentiality and integrity domains, with no availability impact reported under the current CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N)."
}
CVE-2026-70728: Oracle Autonomous Health Framework Vulnerability (HIGH Severity, CVSS: 8.5) - Sceawere