Sceawere
Vulnerability Detail
CVE-2026-70761UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Risk Management Takeover Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Risk Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Risk Management. Successful attacks of this vulnerability can result in takeover of Oracle Risk Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Risk Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Risk Management. Successful attacks of this vulnerability can result in takeover of Oracle Risk Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:17:28.710Z",
"pubdate": "2026-08-18T21:17:28.710Z",
"executiveSummary": "An easily exploitable vulnerability exists within the Internal Operations component of the Oracle Risk Management product in Oracle E-Business Suite versions 12.2.3-12.2.15. This security flaw allows a remote, low-privileged attacker with network access via HTTP to compromise the targeted application.\nSuccessful exploitation of this vulnerability achieves a complete system takeover of Oracle Risk Management, impacting confidentiality, integrity, and availability with a CVSS 3.1 Base Score of 8.8. The attack requires low privileges, no user interaction, and network connectivity over HTTP.\nGiven the severity of the potential impact, organizations utilizing affected versions of Oracle Risk Management face significant risk regarding unauthorized data access, system modification, and service disruption. Immediate remediation via official vendor patches is strongly advised.",
"technicalDetails": "The vulnerability resides in the Internal Operations component of Oracle Risk Management within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is exposed via network protocols using HTTP, allowing authenticated attackers with low privileges to interact with vulnerable internal routines.\nThe attack vector is network-based (AV:N), with low attack complexity (AC:L), requiring low privileges (PR:L) and no user interaction (UI:N). The scope is unchanged (S:U), meaning the vulnerability directly impacts the security context of the vulnerable Oracle Risk Management component.\nThe attack flow begins with a threat actor authenticating to the Oracle E-Business Suite environment with low-privileged credentials. Leveraging network access via HTTP, the attacker sends crafted requests targeting the vulnerable Internal Operations component.\nDue to insufficient input validation, authorization checks, or flawed internal logic within the component, the crafted payload is processed improperly. This enables the attacker to bypass access controls and execute unauthorized administrative or system-level operations.\nPost-exploitation impact includes a complete takeover of Oracle Risk Management (C:H, I:H, A:H). The attacker can read, modify, or delete sensitive business risk data, manipulate system configurations, and disrupt availability, fully compromising the CIA triad for the affected application."
}