Junglewise Threat Intelligence

CVE-2026-70844: Oracle E-Business Suite Loans unauthorized data access

CVE-2026-70844 · Severity: high · CVSS 7.1 · Published 2026-08-18

Technologies: Oracle Loans, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite Loans is a financial management module used by enterprises to administer lending operations and loan portfolios. An attacker with low-level network access can exploit this vulnerability to read sensitive financial data, modify loan records, or delete transaction information, potentially causing financial data corruption and compliance violations.

Technical details

The vulnerability in the Oracle Loans product (component: Internal Operations) allows an authenticated attacker to bypass authorization controls and access restricted data or perform unauthorized modifications. The flaw is exploitable over the network via HTTP with low privileges and does not require user interaction. Successful exploitation grants unauthorized read access to confidential loan data and limited write access (update/insert/delete) to certain Loans-accessible data. The vulnerability affects E-Business Suite versions 12.2.3 through 12.2.15; patch availability and fix status depend on Oracle's Critical Patch Update releases.

Affected products

  • Oracle E-Business Suite 12.2.3–12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats