Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-70689
Oracle Essbase vulnerability analysis and mitigation

Overview

CVE-2026-70689 is a critical improper access control vulnerability in Oracle Essbase (component: Infrastructure) that allows unauthenticated remote attackers to fully compromise the affected system via HTTP. The only supported version affected is 21.8.1.0.0. Oracle disclosed and patched this vulnerability on August 18, 2026, as part of its Critical Security Patch Update (CSPU) for August 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory).

Technical details

The vulnerability is classified under CWE-284 (Improper Access Control) and resides in the Infrastructure component of Oracle Essbase. An unauthenticated attacker with network access via HTTP can exploit this flaw without any user interaction or special privileges, making it trivially automatable. The attack complexity is low and the scope is unchanged, meaning the attacker can directly compromise the Essbase system without pivoting through other components. No detailed technical write-up or public proof-of-concept code has been identified at this time (Oracle Advisory).

Impact

Successful exploitation results in a complete takeover of Oracle Essbase, with high impact to confidentiality, integrity, and availability. An attacker could execute arbitrary operations, read or exfiltrate sensitive business analytics and financial data stored in Essbase, modify or destroy system data, and disrupt service availability. Given that Oracle Essbase is commonly used for enterprise performance management and financial analytics, compromise could expose highly sensitive corporate data and enable further lateral movement within the enterprise environment (Oracle Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of reporting. The vulnerability is rated as automatable by NVD SSVC analysis, with a technical impact of "total." The EPSS score is approximately 0.486%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Oracle Advisory, Tenable Plugin).

Mitigation and workarounds

Oracle has released a patch for Oracle Essbase version 21.8.1.0.0 as part of the August 2026 Critical Security Patch Update (CSPU). Organizations should apply this patch immediately. As a temporary workaround prior to patching, Oracle recommends restricting network access to Oracle Essbase HTTP interfaces to trusted networks only and implementing network segmentation to limit exposure to unauthenticated users. Oracle strongly cautions that workarounds do not address the underlying vulnerability and should not be considered long-term solutions (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle Essbase vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-70689CRITICAL9.8
  • Oracle Essbase logoOracle Essbase
  • cpe:2.3:a:oracle:essbase
NoNoAug 18, 2026
CVE-2026-70688HIGH8.8
  • Oracle Essbase logoOracle Essbase
  • cpe:2.3:a:oracle:essbase
NoNoAug 18, 2026
CVE-2025-61763HIGH8.1
  • Oracle Essbase logoOracle Essbase
  • cpe:2.3:a:oracle:essbase
NoNoOct 21, 2025
CVE-2023-21944MEDIUM5.3
  • Oracle Essbase logoOracle Essbase
  • cpe:2.3:a:oracle:essbase
NoYesApr 18, 2023
CVE-2023-22010LOW2.2
  • Oracle Essbase logoOracle Essbase
  • cpe:2.3:a:oracle:essbase
NoYesJul 18, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management