Junglewise Threat Intelligence

CVE-2026-70732: Oracle Mobile Application Server data exposure in MWA Terminal Server

CVE-2026-70732 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Technologies: Oracle Mobile Application Server. Vendors: Oracle.

Executive brief

Oracle Mobile Application Server is a component of Oracle E-Business Suite that processes mobile application requests. This vulnerability allows an authenticated attacker with network access to bypass authorization controls and gain unauthorized access to sensitive business data stored within the Mobile Application Server. Exploitation is straightforward and requires only standard HTTP access, putting customer data and system confidentiality at risk.

Technical details

This vulnerability in the MWA Terminal Server component of Oracle Mobile Application Server is an authorization bypass affecting versions 12.2.3 through 12.2.15. The flaw allows a low-privileged, authenticated attacker with network-level HTTP access to read sensitive data without proper access controls. The vulnerability does not enable data modification or system availability impact. No patch availability information is currently provided in the advisory, and there is no evidence of active exploitation in the wild as of the publication date.

Affected products

  • Oracle Mobile Application Server 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats