Junglewise Threat Intelligence

CVE-2026-70932: Oracle Order Management privilege escalation in Product Diagnostic Tools

CVE-2026-70932 · Severity: high · CVSS 7.2 · Published 2026-08-18

Technologies: Oracle Order Management. Vendors: Oracle.

Executive brief

Oracle Order Management is a critical component of Oracle E-Business Suite that manages order processing and fulfillment for enterprises. This vulnerability allows a high-privileged local attacker to modify or delete critical business data and access confidential order information, potentially disrupting operations and exposing sensitive customer or financial data.

Technical details

A local privilege escalation vulnerability exists in the Product Diagnostic Tools component of Oracle Order Management. The vulnerability is difficult to exploit and requires local infrastructure access and high privileges, but does not require user interaction. Successful exploitation allows an attacker to achieve unauthorized creation, deletion, or modification of critical data, as well as complete access to all Order Management data. The scope is changed, indicating that exploitation may impact systems beyond Order Management itself. The vulnerability affects versions 12.2.3 through 12.2.15. Patches are expected to be available through Oracle's standard Critical Patch Update process.

Affected products

  • Oracle Order Management 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats