
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-70807 is an improper access control vulnerability (authorization bypass) in the Oracle Call Center Technology component of Oracle E-Business Suite, specifically within the Internal Operations sub-component. It affects supported versions 12.2.3 through 12.2.15. The vulnerability was published on August 18, 2026, with a patch made available via Oracle's Critical Security Patch Update (CSPUAUG2026) on August 27, 2026. It carries a CVSS v3.1 base score of 8.5 (High) (Oracle Advisory, Feedly).
The vulnerability is classified as CWE-284 (Improper Access Control), representing an authorization bypass in the Internal Operations component of Oracle Call Center Technology. A low-privileged attacker with network access via HTTP can exploit this flaw without requiring user interaction, making it easily exploitable under standard network conditions. The vulnerability has a changed scope, meaning successful exploitation can cascade to impact additional products beyond Oracle Call Center Technology itself. No detailed technical write-ups or public proof-of-concept code have been identified at this time (Oracle Advisory).
Successful exploitation allows a low-privileged attacker to gain unauthorized access to all data accessible by Oracle Call Center Technology (high confidentiality impact), as well as unauthorized update, insert, or delete access to some of that data (low integrity impact). There is no availability impact. The scope change indicates that attacks may significantly affect additional products within the Oracle E-Business Suite ecosystem beyond the directly vulnerable component, increasing the potential blast radius of a successful attack (Oracle Advisory).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.00316 (0.316%), indicating a low probability of exploitation in the near term. NVD's SSVC assessment classifies exploitation as "none" and the attack as not automatable, as it requires a low-privileged authenticated account (Oracle Advisory).
Oracle has released a patch for CVE-2026-70807 as part of the Critical Security Patch Update for August 2026 (CSPUAUG2026). Organizations running Oracle E-Business Suite versions 12.2.3 through 12.2.15 should apply the patch immediately. As interim measures, restrict network access to Oracle E-Business Suite Call Center Technology to trusted networks only, monitor access logs for suspicious activity from low-privileged accounts, and consider network segmentation to limit lateral impact if the component is compromised. Oracle strongly recommends against relying on network-blocking workarounds as a long-term solution (Oracle Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."