Sceawere

Vulnerability Detail

CVE-2026-70802UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Public Sector Human Resources Compromise Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Public Sector Human Resources
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Human Resources.
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Human Resources. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.0",
  "pubDate": "2026-08-18T21:17:34.383Z",
  "pubdate": "2026-08-18T21:17:34.383Z",
  "executiveSummary": "A security vulnerability affects the Oracle Public Sector Human Resources product within Oracle E-Business Suite, specifically within the Regression Testing component. This vulnerability allows an attacker with high privileges and network access via HTTP to execute a complex exploitation vector against the target system. Due to architectural characteristics, a successful attack introduces a significant scope change, leading to potential impacts far beyond the initial component.\nThe risk implications are severe, as successful exploitation results in the complete takeover of Oracle Public Sector Human Resources, accompanied by high-severity impacts across confidentiality, integrity, and availability. The CVSS 3.1 base score for this flaw is 8.0, reflecting the gravity of the potential compromise despite the requirement for high privileges and high attack complexity.\nSupported versions 12.2.3 through 12.2.15 of Oracle Public Sector Human Resources are confirmed to be vulnerable. Threat actors must possess administrative or high-level privileges within the application environment and network connectivity via the HTTP protocol to initiate an attack sequence.",
  "technicalDetails": "The vulnerability resides in the Regression Testing component of Oracle Public Sector Human Resources within Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. The flaw is exposed via network access utilizing the HTTP protocol, making it accessible to entities capable of communicating with the application tier hosting the E-Business Suite architecture.\nExploitation of this vulnerability requires high privileges within the target application and involves high attack complexity (AC:H), implying that the attacker must perform preparatory steps, overcome specific race conditions, or manipulate complex environmental parameters to achieve successful exploitation. Although the entry point is localized to the Oracle Public Sector Human Resources product, the vulnerability exhibits a scope change (S:C), indicating that successful exploitation breaks security boundaries, allowing the attacker to propagate impact to underlying infrastructure, integrated modules, or additional products managed within the broader Oracle E-Business Suite ecosystem.\nThe attack flow commences with the adversary authenticating to the application with high-level administrative or privileged credentials. Leveraging network access via HTTP, the attacker interacts with the vulnerable Regression Testing interface or underlying execution handlers. By supplying crafted inputs or manipulating execution routines within the vulnerable component, the attacker subverts the intended logic of the application. This manipulation bypasses security controls governing internal component interactions, leading to unauthorized command execution or data manipulation.\nPost-exploitation impact encompasses the total takeover of Oracle Public Sector Human Resources, characterized by complete loss of confidentiality, integrity, and availability (C:H/I:H/A:H). Because of the scope change vector, the attacker can leverage the compromised context to pivot, escalate privileges across adjacent administrative boundaries, and compromise auxiliary assets integrated with the E-Business Suite deployment."
}
CVE-2026-70802: Oracle Public Sector Human Resources Compromise Vulnerability (HIGH Severity, CVSS: 8.0) - Sceawere