Sceawere
Vulnerability Detail
CVE-2026-70835UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle iRecruitment Authorization Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle iRecruitment
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iRecruitment accessible data as well as unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle iRecruitment accessible data as well as unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-08-18T21:17:38.920Z",
"pubdate": "2026-08-18T21:17:38.920Z",
"executiveSummary": "A security vulnerability has been identified within the Internal Operations component of the Oracle iRecruitment product in Oracle E-Business Suite versions 12.2.3-12.2.15. This flaw allows a low-privileged authenticated attacker with network access via HTTP to compromise the application.\nSuccessful exploitation of this vulnerability can lead to severe impacts on data confidentiality and integrity, resulting in unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to sensitive information accessible via Oracle iRecruitment.\nThe vulnerability is classified with a CVSS 3.1 Base Score of 8.1, reflecting high impacts on confidentiality and integrity with no availability impact. The CVSS vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).\nThe attack vector is network-based, requiring low privileges and no user interaction, making it easily exploitable under the specified conditions.",
"technicalDetails": "The vulnerability affects the Internal Operations component of Oracle iRecruitment within Oracle E-Business Suite versions 12.2.3 through 12.2.15.\nExploitation requires network access via the HTTP protocol, meaning the target application must be reachable over the network by the attacker.\nThe attacker must possess low-privileged access to the system, but requires no user interaction to successfully execute the attack.\nThe root cause stems from insufficient access controls or authorization validation within the Internal Operations component, allowing authenticated users to transcend their intended privilege boundaries.\nThe attack flow begins with the low-privileged attacker sending crafted HTTP requests directly to the vulnerable Oracle iRecruitment endpoints.\nBecause the application fails to adequately enforce authorization checks on critical functions handled by the Internal Operations component, the malicious HTTP payloads are processed successfully.\nUpon successful processing, the post-exploitation impact includes unauthorized read access to critical and sensitive data, as well as unauthorized write, update, and deletion capabilities over Oracle iRecruitment accessible data.\nThe scope remains unchanged (S:U), but the combination of high confidentiality (C:H) and high integrity (I:H) impacts present a significant risk to the integrity and privacy of enterprise recruitment data stored within the Oracle E-Business Suite environment."
}