Sceawere

Vulnerability Detail

CVE-2026-70852UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Oracle Demand Planning Unauthorized Data Access

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
3h ago
Vendor
Oracle Corporation
Product
Oracle Demand Planning
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demand Planning. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data as well as unauthorized update, insert or delete access to some of Oracle Demand Planning accessible data.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demand Planning. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data as well as unauthorized update, insert or delete access to some of Oracle Demand Planning accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-08-18T21:17:41.210Z",
  "pubdate": "2026-08-18T21:17:41.210Z",
  "executiveSummary": "An easily exploitable vulnerability exists within the Internal Operations component of the Oracle Demand Planning product, specifically affecting supported versions 12.1 and 12.2. This security flaw allows unauthenticated threat actors with network access via the HTTP protocol to compromise the targeted application without requiring user interaction.\nSuccessful exploitation of this vulnerability has severe implications for data confidentiality and integrity. An attacker can achieve unauthorized access to critical data, obtain complete access to all data accessible within Oracle Demand Planning, and execute unauthorized insert, update, or delete operations against a subset of the accessible data sets.\nThe vulnerability carries a CVSS 3.1 Base Score of 8.2, reflecting high confidentiality impact and low-to-moderate integrity impact, with no availability disruption. The attack vector is network-based, featuring low attack complexity and requiring zero privileges or user interaction, making it a high-risk entry point for malicious actors targeting enterprise supply chain infrastructure.",
  "technicalDetails": "The vulnerability resides in the Internal Operations component of Oracle Demand Planning versions 12.1 and 12.2. The root cause stems from improper input validation, weak access control enforcement, or missing authentication mechanisms within HTTP-exposed endpoints handling internal operations.\nExploitation is conducted remotely over the network using the HTTP protocol. Because the affected component fails to properly authenticate incoming requests and validate authorization boundaries, an unauthenticated attacker can bypass security controls directly. The attacker crafts malicious HTTP requests targeted at vulnerable endpoints exposed by the Internal Operations module.\nThe attack flow proceeds as follows: First, the unauthenticated actor establishes network connectivity to the target Oracle Demand Planning instance over HTTP. Second, the actor transmits specially crafted requests to the vulnerable Internal Operations component, omitting any valid session tokens or credentials, as the endpoint incorrectly processes unauthenticated traffic. Third, the application processes the request, exposing sensitive database contents or executing unauthorized data modification instructions (insert, update, delete) depending on the parameters supplied in the payload.\nThe post-exploitation impact allows the adversary to exfiltrate critical proprietary data and perform unauthorized state changes on accessible data repositories, undermining the integrity of the supply chain planning environment. The attack requires no prior privileges (PR:N) and no user interaction (UI:N), with a low attack complexity (AC:L) via a network vector (AV:N), resulting in a Scope-Unchanged (S:U) vector where confidentiality is severely impacted (C:H) and integrity is partially compromised (I:L)."
}
CVE-2026-70852: Oracle Demand Planning Unauthorized Data Access (HIGH Severity, CVSS: 8.2) - Sceawere