Sceawere

Vulnerability Detail

CVE-2026-70796UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle General Ledger Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle General Ledger
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle General Ledger executes to compromise Oracle General Ledger. While the vulnerability is in Oracle General Ledger, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data.
Vector String
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle General Ledger executes to compromise Oracle General Ledger. While the vulnerability is in Oracle General Ledger, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle General Ledger accessible data as well as unauthorized access to critical data or complete access to all Oracle General Ledger accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-18T21:17:33.547Z",
  "pubdate": "2026-08-18T21:17:33.547Z",
  "executiveSummary": "A vulnerability exists within the Internal Operations component of Oracle General Ledger in Oracle E-Business Suite versions 12.2.3 through 12.2.15, posing significant risk to enterprise database integrity and confidentiality.\nThe flaw allows a highly privileged attacker with pre-existing logon access to the underlying infrastructure where Oracle General Ledger executes to compromise the application.\nAlthough the vulnerable code resides within Oracle General Ledger, successful exploitation triggers a scope change that can significantly impact additional integrated products and peripheral systems.\nAttack consequences include unauthorized creation, deletion, modification, and access to critical data or complete datasets accessible by Oracle General Ledger.\nThe vulnerability is difficult to exploit, requiring specific high-level privileges and local infrastructure access, but yields severe confidentiality and integrity impacts as reflected by its CVSS 3.1 Base Score of 7.2.",
  "technicalDetails": "The vulnerability affects the Internal Operations component of Oracle General Ledger across supported versions 12.2.3 through 12.2.15.\nExploitation requires the attacker to possess high privileges and local logon access to the host infrastructure hosting the Oracle General Ledger execution environment, denoting an Attack Vector (AV:L) of Local and High Privilege Requirements (PR:H).\nThe attack complexity is rated as high (AC:H), indicating that successful exploitation demands precise conditions, complex preconditions, or specialized manipulation of the execution environment by the threat actor.\nUser interaction is not required (UI:N), allowing the attacker to execute the attack sequence independently once prerequisites are met.\nDue to architectural interactions within the enterprise environment, the vulnerability exhibits a scope change (S:C), meaning successful exploitation breaks standard security boundaries and extends adverse impacts beyond the immediate Oracle General Ledger component to significantly affect additional products.\nThe attack flow involves leveraging local infrastructure access to interact with internal operational mechanics of Oracle General Ledger, bypassing localized access controls due to high-privilege context abuse.\nPost-exploitation impact encompasses severe breaches of CIA triads, specifically yielding high impacts on Confidentiality (C:H) and Integrity (I:H), with no direct impact on Availability (A:N).\nThe resulting state permits unauthorized actors to perform comprehensive data manipulation, including the creation, modification, and deletion of critical financial and operational records, alongside unauthorized data exfiltration of all accessible Oracle General Ledger information assets."
}
CVE-2026-70796: Oracle General Ledger Privilege Escalation Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere