Sceawere
Vulnerability Detail
CVE-2026-70731UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Autonomous Health Framework Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.4
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Autonomous Health Framework
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. While the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework.
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. While the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 8.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.4",
"pubDate": "2026-08-18T21:17:25.730Z",
"pubdate": "2026-08-18T21:17:25.730Z",
"executiveSummary": "A security vulnerability has been identified within the Oracle Autonomous Health Framework, specifically affecting the Trace File Analyzer component. This vulnerability allows a low-privileged attacker with local logon access to the underlying infrastructure to compromise the integrity and availability of the framework.\nThe affected product versions include 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, and 26.5.2. The vulnerability carries a CVSS 3.1 Base Score of 8.4, with a vector of CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H, highlighting that while the flaw originates within the Oracle Autonomous Health Framework, successful exploitation introduces a significant scope change that can impact additional downstream products and shared infrastructure.\nExploitation requires local access with low privileges and no user interaction, but presents a severe risk profile due to the potential for unauthorized data manipulation and complete denial of service conditions. Successful attacks enable malicious actors to execute unauthorized creation, deletion, or modification of critical data accessible to the framework, as well as trigger repeatable application hangs or system crashes.",
"technicalDetails": "The vulnerability resides in the Trace File Analyzer component of the Oracle Autonomous Health Framework across versions 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, and 26.5.2. The root cause stems from insufficient access controls or insecure handling of local operations within the component, which permits authenticated local users to interact with sensitive routines or data stores beyond their intended privilege boundary.\nThe attack vector is classified as local (AV:L), meaning the adversary must already possess interactive logon capabilities or the ability to execute code on the host operating system infrastructure where the Oracle Autonomous Health Framework is deployed. The attack complexity is low (AC:L), requiring no specialized race conditions or complex environmental manipulation. Furthermore, the attack requires low privileges (PR:L) and zero user interaction (UI:N), allowing standard, unprivileged local system accounts to initiate the attack flow.\nThe attack flow proceeds as follows: First, the low-privileged attacker establishes a local session on the target infrastructure. Second, the attacker leverages their existing local access to interact directly with vulnerable interfaces or mechanisms exposed by the Trace File Analyzer component of the Oracle Autonomous Health Framework. Third, due to inadequate input validation or improper authorization checks within the targeted component, the attacker issues malicious inputs or commands that bypass intended security boundaries. Because the vulnerability involves a scope change (S:C), the compromise extends beyond the immediate boundary of the Oracle Autonomous Health Framework, potentially affecting core underlying infrastructure or integrated products.\nUpon successful exploitation, the payload behavior manifests in two primary impact domains: Integrity (I:H) and Availability (A:H). The attacker gains unauthorized capability to create, delete, or modify critical data files or repository contents accessible to the Oracle Autonomous Health Framework, leading to potential data corruption or unauthorized tampering. Additionally, the attacker can intentionally trigger application faults or resource exhaustion conditions that result in a frequently repeatable complete denial of service, causing the Oracle Autonomous Health Framework to hang or crash entirely."
}