AI for Security Summit: Join Figma, Perplexity & Wiz. [Register]

CVE-2026-70807
Oracle E-Business Suite vulnerability analysis and mitigation

Overview

CVE-2026-70807 is an improper access control vulnerability (authorization bypass) in the Oracle Call Center Technology component of Oracle E-Business Suite, specifically within the Internal Operations sub-component. It affects supported versions 12.2.3 through 12.2.15. The vulnerability was published on August 18, 2026, with a patch made available via Oracle's Critical Security Patch Update (CSPUAUG2026) on August 27, 2026. It carries a CVSS v3.1 base score of 8.5 (High) (Oracle Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control), representing an authorization bypass in the Internal Operations component of Oracle Call Center Technology. A low-privileged attacker with network access via HTTP can exploit this flaw without requiring user interaction, making it easily exploitable under standard network conditions. The vulnerability has a changed scope, meaning successful exploitation can cascade to impact additional products beyond Oracle Call Center Technology itself. No detailed technical write-ups or public proof-of-concept code have been identified at this time (Oracle Advisory).

Impact

Successful exploitation allows a low-privileged attacker to gain unauthorized access to all data accessible by Oracle Call Center Technology (high confidentiality impact), as well as unauthorized update, insert, or delete access to some of that data (low integrity impact). There is no availability impact. The scope change indicates that attacks may significantly affect additional products within the Oracle E-Business Suite ecosystem beyond the directly vulnerable component, increasing the potential blast radius of a successful attack (Oracle Advisory).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.00316 (0.316%), indicating a low probability of exploitation in the near term. NVD's SSVC assessment classifies exploitation as "none" and the attack as not automatable, as it requires a low-privileged authenticated account (Oracle Advisory).

Mitigation and workarounds

Oracle has released a patch for CVE-2026-70807 as part of the Critical Security Patch Update for August 2026 (CSPUAUG2026). Organizations running Oracle E-Business Suite versions 12.2.3 through 12.2.15 should apply the patch immediately. As interim measures, restrict network access to Oracle E-Business Suite Call Center Technology to trusted networks only, monitor access logs for suspicious activity from low-privileged accounts, and consider network segmentation to limit lateral impact if the component is compromised. Oracle strongly recommends against relying on network-blocking workarounds as a long-term solution (Oracle Advisory).

Additional resources


SourceThis report was generated using AI

Related Oracle E-Business Suite vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-70813HIGH8.8
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoAug 18, 2026
CVE-2026-70812HIGH8.8
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoAug 18, 2026
CVE-2026-70807HIGH8.5
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoAug 18, 2026
CVE-2026-70814HIGH8.1
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoAug 18, 2026
CVE-2026-70837HIGH7.1
  • Oracle E-Business Suite logoOracle E-Business Suite
  • cpe:2.3:a:oracle:e-business_suite
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management