Description
Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Advanced Outbound Telephony allows a low‑privileged attacker who can reach the system over HTTP to gain control of the product. The vulnerability is an improper access control flaw (CWE‑284). Based on the description, it is inferred that the attacker can execute arbitrary commands, bypassing the intended privilege boundaries and potentially affecting the entire telephony service. The impact covers confidentiality, integrity, and availability of the application, as the attacker can modify or erase data and disrupt operations.

Affected Systems

Oracle Advanced Outbound Telephony component Internal Operations versions 12.2.3 through 12.2.15 are affected.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 categorizes the flaw as high severity. The EPSS score of less than 1 % indicates that exploitation has been historically rare, and the version is not listed in the CISA KEV catalog. Attackers require only network access to an exposed HTTP endpoint and no user interaction. Based on the description, it is inferred that successful exploitation can lead to full takeover of the telephony service, compromising any data and potentially escalating privileges on the underlying host.

Generated by OpenCVE AI on August 5, 2026 at 01:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Security Update from the July 2026 critical patch update that resolves this issue.
  • Restrict network access to the Oracle Advanced Outbound Telephony HTTP endpoints to trusted IP ranges or block external traffic until the patch can be applied.
  • Configure the product to run with the least privilege; ensure that the accounts used by the telephony service are not part of privileged groups and enforce strong authentication.

Generated by OpenCVE AI on August 5, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTP in Oracle Advanced Outbound Telephony

Sat, 01 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unauthenticated HTTP in Oracle Advanced Outbound Telephony

Mon, 27 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via HTTP in Oracle Advanced Outbound Telephony
Weaknesses CWE-307

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via HTTP in Oracle Advanced Outbound Telephony
Weaknesses CWE-284
CWE-307

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle advanced Outbound Telephony
CPEs cpe:2.3:a:oracle:advanced_outbound_telephony:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle advanced Outbound Telephony
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Advanced Outbound Telephony
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T03:55:39.857Z

Reserved: 2026-07-08T15:51:55.594Z

Link: CVE-2026-60829

cve-icon Vulnrichment

Updated: 2026-07-24T15:03:42.941Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:20.890

Modified: 2026-07-31T17:39:02.080

Link: CVE-2026-60829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:45:04Z

Weaknesses