Sceawere

Vulnerability Detail

CVE-2026-70805UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Project Planning Authorization Bypass

Vulnerability Metadata

Severity
High
Score / CVSS
8.1
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Project Planning and Control
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Planning and Control. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Planning and Control accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Planning and Control accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Planning and Control. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Project Planning and Control accessible data as well as unauthorized access to critical data or complete access to all Oracle Project Planning and Control accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.1",
  "pubDate": "2026-08-18T21:17:34.813Z",
  "pubdate": "2026-08-18T21:17:34.813Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Change Management component of Oracle Project Planning and Control, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw permits a low-privileged authenticated attacker with network access via HTTP to compromise the confidentiality and integrity of the application. Successful exploitation enables unauthorized read, create, delete, and modify operations against critical data accessible to Oracle Project Planning and Control. The vulnerability presents significant risk due to low attack complexity and the absence of user interaction requirements, allowing malicious actors with minimal initial access privileges to manipulate or exfiltrate sensitive business project data.",
  "technicalDetails": "The vulnerability resides in the Change Management component of Oracle Project Planning and Control, affecting supported versions 12.2.3 through 12.2.15. The root cause stems from insufficient authorization checks and access control enforcement within the web-based request handling mechanisms exposed over the HTTP protocol. Because the attack vector is network-based (AV:N) with low attack complexity (AC:L) and requires low privileges (PR:L), an authenticated attacker can directly interact with vulnerable endpoints without needing user interaction (UI:N). The attack flow begins with the adversary establishing an HTTP session using low-privileged credentials within the Oracle E-Business Suite environment. By crafting specialized HTTP requests targeting the Change Management component, the attacker bypasses intended logical access controls enforced by the application layer. The lack of robust authorization validation allows the attacker's payload to execute unauthorized database queries or application-level transactions. Post-exploitation impact includes severe compromise of data integrity and confidentiality (CVSS:3.1/C:H/I:H/A:N), manifesting as unauthorized creation, modification, or deletion of critical project planning data, as well as the unauthorized retrieval of sensitive information accessible to the Oracle Project Planning and Control product suite."
}
CVE-2026-70805: Oracle Project Planning Authorization Bypass (HIGH Severity, CVSS: 8.1) - Sceawere