Junglewise Threat Intelligence

CVE-2026-70728: Oracle Autonomous Health Framework privilege escalation in Trace File Analyzer

CVE-2026-70728 · Severity: high · CVSS 8.5 · Published 2026-08-18

Technologies: Oracle Autonomous Health Framework. Vendors: Oracle.

Executive brief

Oracle Autonomous Health Framework is a monitoring and diagnostic tool used to track the health of Oracle database systems. An attacker with low-level network access can exploit a vulnerability in the Trace File Analyzer component to gain unauthorized access to sensitive database information and modify data without proper authorization. This could lead to exposure of critical business data stored in Oracle databases and potential corruption of audit logs or configuration data.

Technical details

The vulnerability in the Trace File Analyzer component of Oracle Autonomous Health Framework is easily exploitable via the network by a low-privileged attacker using HTTP requests. No user interaction is required. An attacker with network access and low privileges can achieve high confidentiality impact (unauthorized read access to critical data) and limited integrity impact (unauthorized update, insert, or delete of some accessible data). The scope is changed, meaning the vulnerability can impact systems beyond just the Autonomous Health Framework itself. Patch status is unknown; contact Oracle support for remediation guidance.

Affected products

  • Oracle Autonomous Health Framework 26.0–26.1.0, 26.2.0, 26.3.1, 26.5.0, 26.5.2

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory: Published in Oracle Critical Patch Update August 2026

References

Related threats