Sceawere

Vulnerability Detail

CVE-2026-70804UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Public Sector HR Compromise

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Public Sector Human Resources
Attack Type
Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Public Sector Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Public Sector Human Resources accessible data.
Vector String
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Public Sector Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-08-18T21:17:34.667Z",
  "pubdate": "2026-08-18T21:17:34.667Z",
  "executiveSummary": "An exploitable vulnerability exists within the Regression Testing component of the Oracle Public Sector Human Resources product, part of the Oracle E-Business Suite. This security flaw affects supported software versions ranging from 12.2.3 to 12.2.15.\nThe vulnerability is characterized by a high attack complexity and requires a highly privileged attacker with network access via the HTTP protocol to successfully compromise the targeted system. Despite these high prerequisites, a successful exploitation has a significant scope change, meaning that the impact extends beyond the immediate vulnerable component to adversely affect additional products.\nThe primary risk implications involve severe confidentiality and integrity breaches. Successful attacks enable unauthorized actors to execute critical data creation, deletion, and modification operations, as well as gain unauthorized or complete read access to all data accessible within Oracle Public Sector Human Resources. The CVSS 3.1 base score is calculated at 7.7, reflecting the substantial potential impact on data integrity and confidentiality despite the high privilege and attack complexity requirements.",
  "technicalDetails": "The vulnerability resides within the Regression Testing component of Oracle Public Sector Human Resources in Oracle E-Business Suite versions 12.2.3 through 12.2.15. The root cause allows an authenticated adversary possessing elevated privileges to leverage network-based HTTP vectors to interact with vulnerable backend logic, bypassing standard authorization or input validation controls present in the affected subsystem.\nThe exploitation method requires the attacker to authenticate with high privileges within the application environment. Once authenticated, the attacker crafts specialized HTTP requests targeting the vulnerable Regression Testing functionality. Due to insufficient validation and flawed access controls within the component, the crafted payload is processed by the application, leading to unintended state modifications and data exposures.\nThe attack flow proceeds as follows: First, the high-privileged adversary establishes network connectivity to the Oracle E-Business Suite instance over HTTP. Second, the attacker formulates an exploit payload designed to leverage the flaws in the Regression Testing component. Third, the payload is transmitted to the server where the underlying application logic processes the request. Fourth, because of the scope change (S:C) vector, the impact propagates beyond the immediate Oracle Public Sector Human Resources boundaries to affect supplementary integrated products.\nPost-exploitation impact includes the unauthorized creation, deletion, and modification of critical data sets, alongside the complete compromise of confidentiality for all data accessible by or through the Oracle Public Sector Human Resources application. The CVSS vector (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N) indicates Network attack vector (AV:N), High attack complexity (AC:H), High privileges required (PR:H), No user interaction required (UI:N), Changed scope (S:C), High confidentiality impact (C:H), High integrity impact (I:H), and None for availability impact (A:N)."
}
CVE-2026-70804: Oracle Public Sector HR Compromise (HIGH Severity, CVSS: 7.7) - Sceawere