Sceawere

Vulnerability Detail

CVE-2026-70807UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Call Center Technology Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.5
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Call Center Technology
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. While the vulnerability is in Oracle Call Center Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Call Center Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Call Center Technology accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. While the vulnerability is in Oracle Call Center Technology, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Call Center Technology accessible data as well as unauthorized update, insert or delete access to some of Oracle Call Center Technology accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.5",
  "pubDate": "2026-08-18T21:17:35.107Z",
  "pubdate": "2026-08-18T21:17:35.107Z",
  "executiveSummary": "A security vulnerability affecting the Oracle Call Center Technology component of Oracle E-Business Suite has been identified, impacting supported versions 12.2.3 through 12.2.15. This remotely exploitable vulnerability carries a CVSS 3.1 Base Score of 8.5, indicating a severe risk profile driven primarily by high confidentiality and integrity impacts alongside a security scope change.\nThe vulnerability is classified as easily exploitable, requiring low-privileged attacker access via the HTTP protocol over the network. Successful exploitation does not require user interaction. Due to the scope change characteristic of this flaw, a successful attack against the Internal Operations component of Oracle Call Center Technology may significantly impact additional integrated products within the ecosystem.\nFrom an attacker capability perspective, a malicious actor with baseline low-privileged network access can leverage this flaw to execute unauthorized operations. The direct impact encompasses unauthorized access to critical data or complete access to all data accessible by Oracle Call Center Technology, in addition to unauthorized update, insert, or delete capabilities against a subset of accessible data. Organizations utilizing affected versions face significant risk to data integrity and enterprise confidentiality, necessitating immediate patch deployment and strict network monitoring.",
  "technicalDetails": "The vulnerability resides within the Internal Operations component of the Oracle Call Center Technology product, which forms part of the Oracle E-Business Suite architecture. The affected software versions span from 12.2.3 to 12.2.15. The flaw is exposed via network interfaces utilizing the HTTP protocol, making it accessible to any threat actor capable of establishing network connectivity to the target application.\nExploitation requirements are defined by a low attack complexity (AC:L) and low privilege requirements (PR:L), meaning the attacker must possess authenticated access to the application with minimal authorization levels. No user interaction (UI:N) is required for successful exploitation. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N) highlights a scope change (S:C), which indicates that the vulnerability allows a low-privileged user authenticated to the vulnerable component to impact resources and security domains beyond the administrative boundaries of Oracle Call Center Technology.\nThe step-by-step attack flow begins with the threat actor authenticating to the Oracle E-Business Suite environment with low-privileged credentials. The attacker then crafts a malicious HTTP request directed against the vulnerable Internal Operations component of Oracle Call Center Technology. Due to insufficient input validation, authorization checks, or flawed access control enforcement within the application logic, the crafted payload bypasses standard security controls.\nUpon successful processing of the payload, the attack achieves unauthorized data access extending across the core product boundary. Because of the scope change attribute, the privilege escalation or security boundary transgression affects downstream or related products integrated within the Oracle E-Business Suite deployment. The post-exploitation impact includes the full exposure and extraction of critical and sensitive data accessible to Oracle Call Center Technology (Confidentiality: High), alongside the unauthorized modification, insertion, or deletion of specific data sets within the application environment (Integrity: Low), while availability remains unaffected (Availability: None)."
}
CVE-2026-70807: Oracle Call Center Technology Vulnerability (HIGH Severity, CVSS: 8.5) - Sceawere