Sceawere
Vulnerability Detail
CVE-2026-70747UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Customers Online Takeover Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Customers Online
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of this vulnerability can result in takeover of Oracle Customers Online.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Customers Online product of Oracle E-Business Suite (component: Customer Tab). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customers Online. Successful attacks of this vulnerability can result in takeover of Oracle Customers Online. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:17:27.560Z",
"pubdate": "2026-08-18T21:17:27.560Z",
"executiveSummary": "A security vulnerability exists within the Oracle Customers Online product of Oracle E-Business Suite, specifically affecting the Customer Tab component across supported versions 12.2.3 through 12.2.15.\nThe vulnerability is classified as easily exploitable, allowing a low-privileged remote attacker with network access via the HTTP protocol to compromise the affected application.\nSuccessful exploitation of this flaw can lead to a complete takeover of Oracle Customers Online, yielding severe impacts on confidentiality, integrity, and availability with a CVSS 3.1 Base Score of 8.8.\nThe attack requires low privileges and network connectivity, but does not require user interaction, making unauthorized exploitation viable for authenticated users targeting critical enterprise business resources.",
"technicalDetails": "The vulnerability resides in the Customer Tab component of Oracle Customers Online within Oracle E-Business Suite versions 12.2.3 to 12.2.15.\nAttack surface exposure is present over the network via the HTTP protocol, allowing remote threat actors to reach the vulnerable endpoint.\nExploitation requires a low-privileged authenticated user, meaning the attacker must possess valid credentials within the system to interact with the vulnerable component, though no user interaction is required.\nThe attack flow begins when the low-privileged attacker crafts and sends malicious HTTP requests targeted at the Customer Tab component.\nDue to insufficient input validation, authorization checks, or improper handling of parameters within the vulnerable component, the crafted payload bypasses security controls.\nExecution of the payload permits the attacker to elevate privileges or execute unauthorized operations, ultimately resulting in the complete takeover of Oracle Customers Online.\nThe post-exploitation impact includes the compromise of confidentiality, integrity, and availability, granting the attacker full control over the application data, system functionalities, and administrative workflows managed by Oracle Customers Online."
}