Sceawere

Vulnerability Detail

CVE-2026-70827UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle MES Process Manufacturing Disclosure

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle MES for Process Manufacturing
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. While the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. While the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-08-18T21:17:37.833Z",
  "pubdate": "2026-08-18T21:17:37.833Z",
  "executiveSummary": "An easily exploitable vulnerability affects the Internal Operations component of Oracle MES for Process Manufacturing within the Oracle E-Business Suite, specifically versions 12.2.3 through 12.2.15. This security flaw allows a low-privileged attacker with network access via HTTP to compromise the targeted system and achieve unauthorized access to critical data. Due to a scope change, successful exploitation may also significantly impact additional products beyond the immediate vulnerable component. The vulnerability exclusively impacts confidentiality, resulting in unauthorized read access to sensitive information or complete access to all data accessible by Oracle MES for Process Manufacturing. Exploitation requires network connectivity, low privileges, and zero user interaction, yielding a CVSS 3.1 Base Score of 7.7 with a vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N. Organizations utilizing the affected software versions face significant risk regarding data exposure and potential secondary impacts across integrated product architectures, necessitating prompt remediation through applicable vendor patches and strict access controls.",
  "technicalDetails": "The vulnerability resides within the Internal Operations component of Oracle MES for Process Manufacturing, an enterprise module of the Oracle E-Business Suite. It affects supported software versions 12.2.3 through 12.2.15. The flaw is exposed over the network via the HTTP protocol, allowing remote threat actors to interact with vulnerable application endpoints. Exploitation requires low privileges, meaning the attacker must possess authenticated access to the application, albeit at a minimal authorization tier. No user interaction is required for a successful attack, streamlining the exploitation process.\nThe attack vector relies on the network (AV:N) with low attack complexity (AC:L), indicating that the targeted endpoints lack adequate input validation, authorization checks, or access control enforcement within the Internal Operations component. Because the vulnerability exhibits a scope change (S:C), the security scope extends beyond the immediate boundary of Oracle MES for Process Manufacturing, allowing compromised privileges or data flows to impact additional integrated products within the Oracle E-Business Suite ecosystem.\nDuring the attack flow, a malicious actor with low-privileged network access crafts specialized HTTP requests targeting the vulnerable Internal Operations functionality. By bypassing insufficient authorization controls, the attacker interacts with backend logic that improperly handles data queries or object references. This flaw permits the extraction of sensitive information that should otherwise be restricted based on the user's privilege level.\nThe post-exploitation impact is characterized by severe confidentiality breaches (C:H). Successful exploitation results in unauthorized access to critical data or complete access to all data accessible by Oracle MES for Process Manufacturing, as well as potential downstream impacts on other integrated systems due to the scope change. Integrity and availability remain unaffected (I:N, A:N), as the vulnerability vector is strictly confined to unauthorized information disclosure rather than data destruction or system denial of service."
}
CVE-2026-70827: Oracle MES Process Manufacturing Disclosure (HIGH Severity, CVSS: 7.7) - Sceawere