Junglewise Threat Intelligence

CVE-2026-70700: Oracle Payables denial of service via HTTP

CVE-2026-70700 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Payables, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle Payables is a financial management module within Oracle E-Business Suite that handles invoice processing and payment operations. An unauthenticated attacker can remotely crash or hang the Payables service through a simple HTTP request, causing complete service unavailability and disruption to accounts payable operations. No user action or authentication is required for exploitation.

Technical details

This is a denial-of-service vulnerability in Oracle Payables (component: Internal Operations) affecting versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable and requires only network access via HTTP; no authentication or user interaction is required. An unauthenticated remote attacker can send a crafted HTTP request to cause a hang or crash of the Payables service, resulting in complete availability loss. The vendor has assigned CVSS 3.1 score 7.5 (vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H) and has published a fix in their August 2026 CPU (Critical Patch Update).

Affected products

  • Oracle E-Business Suite Payables 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats