Junglewise Threat Intelligence

CVE-2026-70720: Oracle Production Scheduling unauthorized data access in E-Business Suite

CVE-2026-70720 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Production Scheduling. Vendors: Oracle.

Executive brief

Oracle Production Scheduling is a critical component of Oracle E-Business Suite used to manage manufacturing operations and resource planning. A vulnerability in versions 12.2.3 through 12.2.15 allows authenticated users with standard network access to view sensitive operational data they should not have access to, potentially exposing confidential production plans, schedules, and business intelligence.

Technical details

The vulnerability is an unauthorized data access issue in the Internal Operations component of Oracle Production Scheduling. It requires network access via HTTP and authentication as a low-privileged user, but no user interaction is needed to exploit it. The flaw allows attackers to bypass access controls and read sensitive data from the system. The vulnerability affects versions 12.2.3 through 12.2.15 of the product. Oracle has published a security advisory detailing affected versions; patching information should be obtained from official Oracle security channels.

Affected products

  • Oracle Production Scheduling (E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats