Junglewise Threat Intelligence

CVE-2026-70708: Oracle E-Business Suite Sales Foundation auth bypass in Security API

CVE-2026-70708 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite is an enterprise resource planning system used by organizations to manage business operations. A flaw in the Security API component of the Sales Foundation module allows authenticated users to bypass authorization controls and gain unauthorized access to, modify, or delete critical business data. An attacker with low-privilege network access can exploit this to compromise sensitive sales and operational information.

Technical details

This vulnerability is an authorization bypass in the Security API component of Oracle E-Business Suite's Sales Foundation product. The flaw is easily exploitable and requires only network access via HTTP and a low-privilege account; no additional user interaction is needed. An attacker can leverage this to gain unauthorized creation, deletion, or modification access to critical data and complete access to all Sales Foundation accessible data. The vulnerability affects versions 12.2.3 through 12.2.15, and Oracle has released patches as part of their August 2026 security updates.

Affected products

  • Oracle E-Business Suite 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats