Junglewise Threat Intelligence

CVE-2026-70699: Oracle Payments authentication bypass in File Transmission

CVE-2026-70699 · Severity: high · CVSS 7.4 · Published 2026-08-18

Technologies: Oracle E-Business Suite Payments, Oracle Payments. Vendors: Oracle.

Executive brief

Oracle Payments is a critical financial module within Oracle E-Business Suite used to manage payments and fund transfers. This vulnerability allows an unauthenticated attacker with network access to bypass security controls and gain unauthorized access to sensitive financial data, including the ability to create, delete, or modify payment records. An exploit could result in financial fraud, data theft, and operational disruption across affected organizations.

Technical details

This is an authentication bypass vulnerability in the File Transmission component of Oracle Payments within E-Business Suite. An unauthenticated attacker can exploit this via HTTPS (network-accessible) to compromise the system, though the vulnerability is difficult to exploit (high complexity). The attack requires no user interaction and grants the attacker the ability to read, modify, and delete critical financial data within Oracle Payments. Affected versions are 12.2.3 through 12.2.15. Oracle has issued a security patch as part of its Critical Patch Update (CPUAug2026).

Affected products

  • Oracle E-Business Suite Payments 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats