Sceawere
Vulnerability Detail
CVE-2026-70792UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Yard Management Privilege Escalation
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Yard Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:17:32.960Z",
"pubdate": "2026-08-18T21:17:32.960Z",
"executiveSummary": "A security vulnerability affecting the Oracle Yard Management component of Oracle E-Business Suite has been identified, impacting supported versions 12.2.3 through 12.2.15. This vulnerability is classified as easily exploitable, allowing a low-privileged remote attacker with network access via the HTTP protocol to compromise the confidentiality, integrity, and availability of the target system. Successful exploitation of this flaw can result in the complete takeover of the Oracle Yard Management product. Given the high CVSS 3.1 base score of 8.8 and the severity of potential impacts across all CIA triad vectors, this vulnerability poses significant risk to enterprise deployments relying on affected versions of Oracle E-Business Suite. The attack requires low privileges but does not necessitate user interaction, making unauthorized lateral movement or privilege escalation a critical concern for system administrators.",
"technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle Yard Management, part of the Oracle E-Business Suite ecosystem spanning versions 12.2.3 to 12.2.15. The flaw is exposed via network interfaces utilizing the HTTP protocol, allowing remote threat actors who have obtained low-privileged credentials to interact directly with vulnerable application endpoints. Exploitation does not require user interaction, reducing the operational friction typically associated with social engineering vectors. The attack flow begins when an authenticated adversary with minimal privileges crafts malicious HTTP requests directed at unprotected or improperly validated internal operations handlers within Oracle Yard Management. Due to insufficient input validation, improper access controls, or flawed session handling within the affected component, the application fails to properly enforce authorization boundaries between low-privileged users and administrative functions. Consequently, the crafted payload is processed by the underlying application logic, allowing the attacker to execute unauthorized operations. Post-exploitation impact includes complete system compromise, manifesting as the unauthorized modification, deletion, or exfiltration of sensitive data, as well as total loss of service availability and administrative control over the Oracle Yard Management product. The underlying root cause stems from inadequate validation and authorization enforcement within the Internal Operations component exposed over HTTP."
}