Junglewise Threat Intelligence

CVE-2026-70704: Oracle E-Business Suite Trading Community authentication bypass in Party Search UI

CVE-2026-70704 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's Trading Community module includes a party search interface that processes HTTP requests. An unauthenticated attacker can exploit a vulnerability in this component to gain complete control over the Trading Community system, potentially accessing or modifying customer and business data without authorization.

Technical details

This is a difficult-to-exploit vulnerability in the Party Search UI component of Oracle Trading Community (part of E-Business Suite versions 12.2.3–12.2.15). The flaw allows an unauthenticated attacker with network access to send specially crafted HTTP requests that bypass authentication controls. Successful exploitation results in complete system compromise, affecting confidentiality, integrity, and availability. The CVSS 3.1 score of 8.1 reflects the high impact despite the elevated attack complexity. Patch availability through Oracle's Critical Patch Update (CPUAug2026) should be verified with Oracle support.

Affected products

  • Oracle E-Business Suite 12.2.3–12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats