Junglewise Threat Intelligence

CVE-2026-70710: Oracle Sales Foundation authentication bypass in Security API

CVE-2026-70710 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle Sales Foundation is a core enterprise resource planning (ERP) module in Oracle E-Business Suite used to manage sales operations and customer data. This vulnerability in the Security API allows an authenticated attacker with network access to bypass authorization controls and completely compromise the system, potentially exposing or modifying sensitive sales and customer information. The flaw affects all supported versions from 12.2.3 through 12.2.15.

Technical details

This is an authentication bypass or privilege escalation vulnerability in the Security API component of Oracle Sales Foundation. The vulnerability is easily exploitable via HTTP by a low-privileged attacker with network access and requires only valid (low-privilege) credentials—no additional user interaction is needed. Successful exploitation allows complete compromise of the Oracle Sales Foundation application, with impacts to confidentiality, integrity, and availability. The vulnerability affects versions 12.2.3 through 12.2.15 of Oracle E-Business Suite. Patch availability and remediation guidance should be obtained from Oracle's security advisories.

Affected products

  • Oracle E-Business Suite Sales Foundation 12.2.3–12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats