Junglewise Threat Intelligence

CVE-2026-70922: Oracle Financial Services Enterprise Case Management privilege escalation in Web UI

CVE-2026-70922 · Severity: high · CVSS 8.8 · Published 2026-08-18

Vendors: Oracle.

Executive brief

Oracle Financial Services Enterprise Case Management is a system used by financial institutions to manage customer cases and service requests. A vulnerability in the web interface allows a low-privilege attacker with network access to take complete control of the system, potentially compromising sensitive financial customer data and disrupting critical case management operations.

Technical details

This is a privilege escalation vulnerability in the Web UI component of Oracle Financial Services Enterprise Case Management. The vulnerability is easily exploitable and requires only low-privilege authentication and network access via HTTP to trigger. An authenticated attacker can achieve complete system compromise including confidentiality, integrity, and availability impacts (full takeover). The vulnerability affects versions 8.0.8.2 and 8.1.2.11. Patch status and specific root cause details are not available from the advisory text.

Affected products

  • Oracle Financial Services Enterprise Case Management 8.0.8.2, 8.1.2.11

Timeline

  • 2026-08-18: disclosed

References