Sceawere

Vulnerability Detail

CVE-2026-70778UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Customer Care Security Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Customer Care
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Care. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Customer Care, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customer Care accessible data as well as unauthorized access to critical data or complete access to all Oracle Customer Care accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Care. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Customer Care, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Customer Care accessible data as well as unauthorized access to critical data or complete access to all Oracle Customer Care accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-08-18T21:17:30.920Z",
  "pubdate": "2026-08-18T21:17:30.920Z",
  "executiveSummary": "A security vulnerability has been identified within the Internal Operations component of the Oracle Customer Care product, which is part of Oracle E-Business Suite. This vulnerability affects supported software versions 12.2.3 through 12.2.15.\nThe flaw allows a low-privileged attacker with network access via HTTP to compromise the targeted system. Successful exploitation of this vulnerability requires human interaction from a user other than the attacker. Due to the nature of the vulnerability, a successful attack can result in a scope change, meaning that the impact extends beyond Oracle Customer Care to significantly affect additional products.\nThe consequences of successful exploitation include unauthorized creation, deletion, or modification of critical data or all data accessible via Oracle Customer Care, alongside unauthorized access to critical data or complete access to all accessible application data. The vulnerability is rated with a CVSS 3.1 Base Score of 8.7, indicating severe impacts to confidentiality and integrity.\nOrganizations utilizing the affected versions of Oracle Customer Care face elevated risk regarding data exposure and unauthorized data manipulation, necessitating prompt attention to available vendor patches and defensive hardening configurations.",
  "technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle Customer Care, a module included in Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is exposed via the network protocol HTTP, permitting remote interaction from external or internal network locations depending on organizational deployment topologies.\nExploitation of the vulnerability requires a low-privileged authenticated attacker to interact with the vulnerable application interface. Additionally, a successful attack chain strictly requires human interaction from a distinct user, typically involving social engineering or user-driven navigation of a maliciously crafted workflow or request.\nThe attack vector operates over the network via HTTP with low attack complexity (AC:L) and low privilege requirements (PR:L). Because the vulnerability incorporates a scope change (S:C), a successful exploit allows the attacker to transcend the initial security boundaries of Oracle Customer Care, leading to potential security implications and unauthorized interactions across interdependent products within the Oracle E-Business Suite ecosystem.\nUpon successful execution, the payload leverages the application logic flaws to bypass authorization checks. This grants the attacker unauthorized read, write, create, and delete capabilities against critical data sets and all data accessible to the Oracle Customer Care component. The attack directly undermines confidentiality and integrity principles (C:H/I:H), while availability remains unaffected (A:N).\nThe step-by-step attack flow typically involves the low-privileged attacker crafting a malicious HTTP request or payload targeting the Internal Operations component. The attacker then induces a victim user to execute a required action via human interaction. Upon interaction, the application processes the request within an expanded security scope, granting the attacker unauthorized data access and modification privileges across the affected systems."
}
CVE-2026-70778: Oracle Customer Care Security Vulnerability (HIGH Severity, CVSS: 8.7) - Sceawere