Sceawere
Vulnerability Detail
CVE-2026-70918UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Product Hub Takeover Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Product Hub
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Outbound Data). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub. Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-18T21:17:49.583Z",
"pubdate": "2026-08-18T21:17:49.583Z",
"executiveSummary": "A critical security vulnerability has been identified within the Oracle Product Hub component of Oracle E-Business Suite, specifically affecting the Outbound Data module across supported versions 12.2.3 through 12.2.15. This remotely exploitable flaw allows an authenticated attacker with low privileges and network access via the HTTP protocol to achieve a complete system compromise and full takeover of the affected product.\nThe vulnerability carries a CVSS 3.1 Base Score of 8.8, reflecting high severity impacts across confidentiality, integrity, and availability. The attack vector is network-based with low attack complexity, requiring no user interaction. Successful exploitation grants the adversary full administrative or functional control over Oracle Product Hub, exposing the organization to severe operational disruption, data exfiltration, and unauthorized modification of critical enterprise master data managed within the Oracle E-Business Suite ecosystem.",
"technicalDetails": "The vulnerability resides in the Outbound Data component of Oracle Product Hub within Oracle E-Business Suite versions 12.2.3 to 12.2.15. The root cause stems from improper input validation, insecure deserialization, or inadequate authorization enforcement within the data handling routines exposed via HTTP network interfaces.\nExploitation of this flaw requires the attacker to possess low-level privileges within the application and network access to the HTTP listener serving Oracle Product Hub. Because the attack vector is network-based (AV:N) with low attack complexity (AC:L) and zero user interaction requirements (UI:N), an adversary can interact directly with vulnerable endpoints without social engineering constraints.\nThe attack flow proceeds as follows: First, the authenticated low-privileged attacker crafts a malicious HTTP request targeting the Outbound Data processing functionality. Second, the request traverses the network to the vulnerable Oracle E-Business Suite instance, where the input is improperly processed by the vulnerable component. Third, due to the lack of stringent validation or inadequate access controls, the application executes the injected payload or handles manipulated operational parameters. Finally, this execution bypasses intended security boundaries, granting the attacker elevated privileges or arbitrary code execution capabilities.\nPost-exploitation impact is catastrophic, resulting in a full takeover of Oracle Product Hub (C:H, I:H, A:H). The adversary gains the ability to read confidential business data, manipulate outbound data feeds, disrupt core enterprise workflows, and potentially pivot to underlying database resources or other integrated modules within the Oracle E-Business Suite architecture."
}