Sceawere
Vulnerability Detail
CVE-2026-70791UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Transportation Execution Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.6
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Transportation Execution
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Execution, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Transportation Execution accessible data as well as unauthorized read access to a subset of Oracle Transportation Execution accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Transportation Execution product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Execution. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Transportation Execution, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Transportation Execution accessible data as well as unauthorized read access to a subset of Oracle Transportation Execution accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.6",
"pubDate": "2026-08-18T21:17:32.820Z",
"pubdate": "2026-08-18T21:17:32.820Z",
"executiveSummary": "A security vulnerability affecting the Internal Operations component of the Oracle Transportation Execution product within Oracle E-Business Suite versions 12.2.3 through 12.2.15 allows authenticated attackers with low privileges to compromise the system. The flaw is remotely exploitable over HTTP via network access, requiring user interaction from a victim other than the attacker. Due to a scope change, successful exploitation impacts not only Oracle Transportation Execution but also additional secondary products. The resulting impact includes unauthorized creation, deletion, and modification capabilities over critical and all accessible data, alongside unauthorized read access to a subset of sensitive data. With a CVSS 3.1 Base Score of 7.6, this vulnerability presents significant risks to data integrity and confidentiality within enterprise deployments, necessitating immediate remediation efforts by system administrators.",
"technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle Transportation Execution, affecting supported product versions 12.2.3 through 12.2.15. Exploitation requires the attacker to possess low-level network access via the HTTP protocol and authenticated low privileges within the application environment. The attack vector mandates human interaction from a distinct user other than the attacker, typically indicating a scenario such as induced interaction with a malicious payload or crafted interface element. Because the vulnerability features a scope change (S:C), successful execution transcends the security boundaries of the Oracle Transportation Execution product, enabling cascading security implications across interconnected or secondary products within the enterprise architecture. The primary impacts compromise data confidentiality and integrity; the attacker achieves unauthorized read access to a specific subset of data while obtaining comprehensive unauthorized creation, deletion, and modification access to critical data or all data accessible via Oracle Transportation Execution. The step-by-step attack flow involves an authenticated low-privileged adversary transmitting crafted HTTP requests targeting the vulnerable Internal Operations component, leveraging social engineering or routine workflows to induce mandatory human interaction from a third party. Upon successful processing of the payload, the security controls governing cross-component boundaries are bypassed due to the scope change, allowing the attacker to execute unauthorized data manipulation and retrieval actions across the affected and impacted systems."
}