Sceawere

Vulnerability Detail

CVE-2026-70820UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Call Center Technology Takeover Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Call Center Technology
Attack Type
Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology.
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-08-18T21:17:36.897Z",
  "pubdate": "2026-08-18T21:17:36.897Z",
  "executiveSummary": "A vulnerability has been identified within the Oracle Call Center Technology component of Oracle E-Business Suite, specifically affecting supported versions 12.2.3 through 12.2.15. This security flaw allows a highly privileged attacker with network access via the HTTP protocol to compromise the affected product completely.\nSuccessful exploitation of this vulnerability results in the full takeover of Oracle Call Center Technology, causing severe impacts on confidentiality, integrity, and availability. According to the CVSS 3.1 scoring system, the vulnerability receives a Base Score of 7.2, with a vector of CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H.\nThe risk implications are significant due to the potential for complete system compromise within the Internal Operations component. Exploitation requires network connectivity, low attack complexity, and high-level administrative privileges, but does not require user interaction.",
  "technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle Call Center Technology in Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is exposed via the HTTP protocol over the network, allowing authenticated actors possessing elevated administrative privileges to interact with vulnerable internal operational functions.\nThe attack vector is network-based (AV:N), meaning the attacker does not require physical access to the target system. The attack complexity is rated as low (AC:L), indicating that exploitation does not depend on rare race conditions, complex configurations, or specialized environmental states. However, the attack prerequisite dictates high privileges (PR:H), meaning the threat actor must already have authenticated administrative access to the application prior to initiating the exploit sequence.\nNo user interaction (UI:N) is required for successful exploitation, and the scope remains unchanged (S:U). The root cause stems from insecure handling of administrative operations or improper input validation within the internal operational routines of the Oracle Call Center Technology component.\nDuring an attack flow, the adversary leverages their high-privileged network session over HTTP to submit a crafted payload targeting the vulnerable internal operations component. Because input validation or authorization enforcement is insufficient within the target functions, the payload executes successfully within the application context.\nThe post-exploitation impact encompasses a complete takeover of Oracle Call Center Technology (C:H, I:H, A:H). The attacker achieves full control over the confidentiality, integrity, and availability of the component, allowing them to manipulate core application logic, access sensitive operational data, modify system configurations, and disrupt services."
}
CVE-2026-70820: Oracle Call Center Technology Takeover Vulnerability (HIGH Severity, CVSS: 7.2) - Sceawere