Junglewise Threat Intelligence

CVE-2026-70707: Oracle Sales for Handhelds privilege escalation in E-Business Suite

CVE-2026-70707 · Severity: high · CVSS 8.8 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle Sales for Handhelds is a mobile application component of Oracle E-Business Suite used by field sales teams to manage orders and customer data. A low-privilege network attacker with HTTP access can exploit this vulnerability to gain complete control over the application, including unauthorized access to and modification of sensitive sales and customer information, disrupting business operations.

Technical details

This vulnerability in Oracle Sales for Handhelds (component: Internal Operations) is exploitable by a low-privileged attacker with network access via HTTP. The vulnerability allows an authenticated attacker to escalate privileges and achieve complete compromise of the application, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15. The attack requires low privileges and network reachability but no additional user interaction. A successful exploit results in full takeover of the application and potential access to sensitive business data.

Affected products

  • Oracle Sales for Handhelds 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References