Junglewise Threat Intelligence

CVE-2026-70718: Oracle Bills of Material privilege escalation in E-Business Suite

CVE-2026-70718 · Severity: high · CVSS 8.5 · Published 2026-08-18

Technologies: Oracle Bills of Material, Oracle E-Business Suite Bills of Material. Vendors: Oracle.

Executive brief

Oracle Bills of Material is a component of Oracle E-Business Suite used to manage product configurations and manufacturing operations. A vulnerability allows low-privileged users with network access to take over the system and potentially impact other connected applications, compromising the confidentiality, integrity, and availability of critical manufacturing and supply chain data.

Technical details

A difficult-to-exploit vulnerability exists in the Oracle Bills of Material component of E-Business Suite that allows a low-privileged attacker with network access via HTTP to achieve complete system compromise. The vulnerability has a high attack complexity, requiring specific conditions or preconditions, but does not require user interaction and can be exploited by an authenticated user. Successful exploitation results in full takeover of the Bills of Material system with scope change, meaning the compromise extends to other connected products within the E-Business Suite environment. The vulnerability impacts confidentiality, integrity, and availability of affected systems. Versions 12.2.3 through 12.2.15 are affected; patch availability should be confirmed with Oracle security advisories.

Affected products

  • Oracle E-Business Suite Bills of Material 12.2.3 through 12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats