
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-70689 is a critical improper access control vulnerability in Oracle Essbase (component: Infrastructure) that allows unauthenticated remote attackers to fully compromise the affected system via HTTP. The only supported version affected is 21.8.1.0.0. Oracle disclosed and patched this vulnerability on August 18, 2026, as part of its Critical Security Patch Update (CSPU) for August 2026. It carries a CVSS v3.1 base score of 9.8 (Critical) (Oracle Advisory).
The vulnerability is classified under CWE-284 (Improper Access Control) and resides in the Infrastructure component of Oracle Essbase. An unauthenticated attacker with network access via HTTP can exploit this flaw without any user interaction or special privileges, making it trivially automatable. The attack complexity is low and the scope is unchanged, meaning the attacker can directly compromise the Essbase system without pivoting through other components. No detailed technical write-up or public proof-of-concept code has been identified at this time (Oracle Advisory).
Successful exploitation results in a complete takeover of Oracle Essbase, with high impact to confidentiality, integrity, and availability. An attacker could execute arbitrary operations, read or exfiltrate sensitive business analytics and financial data stored in Essbase, modify or destroy system data, and disrupt service availability. Given that Oracle Essbase is commonly used for enterprise performance management and financial analytics, compromise could expose highly sensitive corporate data and enable further lateral movement within the enterprise environment (Oracle Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of reporting. The vulnerability is rated as automatable by NVD SSVC analysis, with a technical impact of "total." The EPSS score is approximately 0.486%, indicating a currently low but non-negligible probability of exploitation in the near term. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported (Oracle Advisory, Tenable Plugin).
Oracle has released a patch for Oracle Essbase version 21.8.1.0.0 as part of the August 2026 Critical Security Patch Update (CSPU). Organizations should apply this patch immediately. As a temporary workaround prior to patching, Oracle recommends restricting network access to Oracle Essbase HTTP interfaces to trusted networks only and implementing network segmentation to limit exposure to unauthenticated users. Oracle strongly cautions that workarounds do not address the underlying vulnerability and should not be considered long-term solutions (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."