Junglewise Threat Intelligence

CVE-2026-70715: Oracle Autonomous Health Framework privilege escalation in Trace File Analyzer

CVE-2026-70715 · Severity: high · CVSS 8.8 · Published 2026-08-18

Technologies: Oracle Autonomous Health Framework. Vendors: Oracle.

Executive brief

Oracle Autonomous Health Framework is a diagnostics and monitoring tool used to manage database systems. An unauthenticated attacker with physical access to the network segment can exploit a vulnerability in the Trace File Analyzer component to gain full control over the framework, potentially compromising the confidentiality, integrity, and availability of the affected system.

Technical details

This vulnerability in Oracle Autonomous Health Framework's Trace File Analyzer component is easily exploitable and requires no authentication or user interaction. The attack vector is adjacent (physical communication segment access), meaning an attacker must be on the same network segment as the hardware running the framework. Successful exploitation allows an unauthenticated attacker to achieve complete system compromise, including full confidentiality, integrity, and availability impacts. The affected versions include 26.0–26.1.0, 26.2.0, 26.3.1, 26.5.0, and 26.5.2. Patch availability status from the advisory is unclear; consult Oracle security bulletins for remediation guidance.

Affected products

  • Oracle Autonomous Health Framework 26.0–26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2

Timeline

  • 2026-08-18: disclosed

References

Related threats