Junglewise Threat Intelligence

CVE-2026-70695: Oracle Payments data access vulnerability in File Transmission

CVE-2026-70695 · Severity: high · CVSS 7.7 · Published 2026-08-18

Technologies: Oracle Payments, Oracle E-Business Suite Payments. Vendors: Oracle.

Executive brief

Oracle Payments, a component of the E-Business Suite used for managing payment processing and financial transactions, contains a vulnerability in its File Transmission feature that allows high-privileged attackers with network access to compromise the system. An attacker can exploit this flaw to read, create, delete, or modify sensitive payment and financial data, potentially affecting multiple interconnected Oracle systems and causing significant data loss or unauthorized access.

Technical details

This is a data access vulnerability in the File Transmission component of Oracle Payments that allows high-privileged attackers (requiring administrative credentials) with network access via HTTP to exploit the flaw. The vulnerability is classified as difficult to exploit and carries a CVSS 3.1 score of 7.7, with impacts on both confidentiality and integrity. Successful exploitation can result in unauthorized creation, deletion, or modification of critical payment data, as well as complete unauthorized access to all Oracle Payments accessible data. The scope is marked as changed, meaning attacks may significantly impact additional Oracle systems beyond Payments itself. Affected versions are Oracle E-Business Suite 12.2.3 through 12.2.15.

Affected products

  • Oracle E-Business Suite Payments 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats