Sceawere
Vulnerability Detail
CVE-2026-70763UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Operations Intelligence Takeover Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Operations Intelligence
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Operations Intelligence. Successful attacks of this vulnerability can result in takeover of Oracle Operations Intelligence.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Operations Intelligence product of Oracle E-Business Suite (component: Daily Business Intelligence). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Operations Intelligence. Successful attacks of this vulnerability can result in takeover of Oracle Operations Intelligence. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-18T21:17:28.943Z",
"pubdate": "2026-08-18T21:17:28.943Z",
"executiveSummary": "A remotely exploitable vulnerability exists within the Oracle Operations Intelligence component of Oracle E-Business Suite, specifically affecting versions 12.2.3 through 12.2.15. This security flaw enables authenticated attackers with low privileges and network access via HTTP to execute unauthorized operations leading to a complete system takeover of the targeted component. The vulnerability presents severe risk implications, as successful exploitation compromises the confidentiality, integrity, and availability of the affected system. While the attack complexity is rated as high, requiring specific conditions or coordination by the adversary, a successful exploit grants the attacker full control over Oracle Operations Intelligence. No user interaction is required for a successful attack, making network accessibility and low-privileged credentials the primary prerequisites for exploitation within the scope of the affected product versions.",
"technicalDetails": "The vulnerability resides in the Daily Business Intelligence component of the Oracle Operations Intelligence product within Oracle E-Business Suite versions 12.2.3 to 12.2.15. The flaw allows a low-privileged authenticated user to leverage network connectivity over the HTTP protocol to interact with vulnerable functions or endpoints within the application. The root cause stems from insufficient validation or improper access control enforcement within the affected component, which permits unauthorized manipulation of application logic or data structures. The attack flow begins when an attacker with valid low-privileged credentials initiates a crafted HTTP request targeting the exposed Daily Business Intelligence interface. Due to the high attack complexity, the attacker must navigate specific preconditions or race conditions to successfully bypass intended security boundaries. Upon successful transmission and processing of the malicious payload, the application improperly processes the input, leading to a compromise of system integrity and confidentiality. Post-exploitation impact results in the complete takeover of Oracle Operations Intelligence, allowing the adversary to exert administrative control, access sensitive operational data, modify system configurations, or disrupt availability. The vector relies entirely on network accessibility (AV:N), elevated execution privileges are constrained to low-privileged accounts (PR:L), user interaction is not required (UI:N), and the scope remains unchanged (S:U) while severely impacting all three pillars of the CIA triad (C:H/I:H/A:H), culminating in a CVSS 3.1 base score of 7.5."
}