Junglewise Threat Intelligence

CVE-2026-70852: Oracle Demand Planning unauthenticated access in Internal Operations

CVE-2026-70852 · Severity: high · CVSS 8.2 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle Demand Planning is a supply chain software component that helps organizations forecast and plan product demand. This vulnerability allows attackers on the network to bypass authentication and gain unauthorized access to sensitive planning data, including the ability to read, modify, or delete critical business information without any credentials.

Technical details

This is an unauthenticated access vulnerability in Oracle Demand Planning's Internal Operations component, accessible via HTTP. The vulnerability requires no authentication, user interaction, or complex configuration; a network-adjacent attacker can exploit it directly. Successful exploitation results in unauthorized read access to all accessible data (high confidentiality impact) and ability to modify or delete some data (limited integrity impact). Affected versions are 12.1 and 12.2; patches are expected from Oracle's Critical Patch Update process.

Affected products

  • Oracle Demand Planning 12.1, 12.2

Timeline

  • 2026-08-18: disclosed

References

Related threats