Description
Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Suite (component: Security API). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Sales Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper authorization vulnerability in the Oracle Sales Foundation Security API, exemplifying CWE-284 (Improper Access Control). A low‑privileged attacker who can reach the exposed HTTP endpoint can exploit this access control weakness to gain unauthorized control of the Sales Foundation instance, potentially leading to full takeover and compromising confidentiality, integrity, and availability of all data accessed through it.

Affected Systems

Oracle Corporation’s Oracle Sales Foundation product, versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS 3.1 base score of 8.8 classifies this as high severity. An EPSS score of less than 1% indicates a low but nonzero probability of real‑world exploitation. This vulnerability is not listed in the CISA KEV catalog. The affected URL is reachable over HTTP from external networks, giving an attacker a network‑level entry vector to the Security API without authenticating originally or with only limited credentials. The weakness stems from lack of proper authorization checks.

Generated by OpenCVE AI on August 25, 2026 at 21:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Sales Foundation patch issued in the August 2026 security advisory.
  • Restrict inbound HTTP traffic to the Sales Foundation’s exposed endpoints to trusted internal hosts or VPN‑segmented networks, limiting exposure to low‑privileged users.
  • Implementation of strict role‑based access control and robust input validation on the Security API to mitigate privilege escalation, addressing the underlying CWE-284 weakness.
  • Enable detailed audit logging for all Security API calls and monitor for anomalous or privileged requests that may indicate exploitation attempts.

Generated by OpenCVE AI on August 25, 2026 at 21:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Oracle e-business Suite
CPEs cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:sales_foundation:-:*:*:*:*:*:*:*
Vendors & Products Oracle e-business Suite

Tue, 25 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title Improper Authorization and Code Injection in Oracle Sales Foundation Security API Allows Low-Privilege Takeover
Weaknesses CWE-269
CWE-285

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Improper Authorization and Code Injection in Oracle Sales Foundation Security API Allows Low-Privilege Takeover
Weaknesses CWE-269
CWE-285

Fri, 21 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Sales Foundation Security API
Weaknesses CWE-284
CWE-94

Wed, 19 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in Oracle Sales Foundation Security API
Weaknesses CWE-284
CWE-94

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Sales Foundation product of Oracle E-Business Suite (component: Security API). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Foundation. Successful attacks of this vulnerability can result in takeover of Oracle Sales Foundation. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle sales Foundation
CPEs cpe:2.3:a:oracle:sales_foundation:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle sales Foundation
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle E-business Suite Sales Foundation
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-26T03:56:16.064Z

Reserved: 2026-08-04T22:06:34.591Z

Link: CVE-2026-70710

cve-icon Vulnrichment

Updated: 2026-08-25T15:09:43.535Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:23.260

Modified: 2026-08-31T15:06:37.810

Link: CVE-2026-70710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:15:13Z

Weaknesses