Description
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in takeover of Oracle iSetup. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability affects Oracle iSetup, a component of Oracle E‑Business Suite’s General Ledger Update Transform and Reports. It allows an attacker who has low‑privileged network access over HTTP to compromise the iSetup service and take full control of the application. Successful exploitation results in confidentiality, integrity, and availability impacts due to the complete takeover of the service.

Affected Systems

Oracle iSetup versions 12.2.3 through 12.2.15 are impacted. These releases are distributed by Oracle Corporation within Oracle E‑Business Suite deployments.

Risk and Exploitability

The CVSS v3.1 base score of 7.5 classifies the issue as high severity. The attack vector requires network access (AV:N), a high effort level (AC:H), and low privilege (PR:L), with no user interaction required (UI:N). The EPSS score of less than 1% indicates a very low current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. Despite the low exploitation probability, the flaw permits complete takeover of iSetup with minimal prerequisites, making it a potential threat for exposed environments.

Generated by OpenCVE AI on August 21, 2026 at 10:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle iSetup patch or upgrade to a version newer than 12.2.15
  • Restrict HTTP access to the iSetup service to trusted networks or VPN tunnels, and enforce firewall rules to limit exposure
  • Implement least‑privilege on accounts that can reach the service and segregate duties to reduce misuse

Generated by OpenCVE AI on August 21, 2026 at 10:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Title High Severity Oracle iSetup Remote Takeover Vulnerability
Weaknesses CWE-20
CWE-284

Fri, 21 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Remote Network Exploitation in Oracle iSetup Allowing Low‑Privilege Takeover
Weaknesses CWE-269
CWE-285

Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Remote Network Exploitation in Oracle iSetup Allowing Low‑Privilege Takeover
Weaknesses CWE-269
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in takeover of Oracle iSetup. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle isetup
CPEs cpe:2.3:a:oracle:isetup:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle isetup
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:12:35.682Z

Reserved: 2026-08-04T22:06:34.591Z

Link: CVE-2026-70713

cve-icon Vulnrichment

Updated: 2026-08-25T15:06:10.501Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:23.610

Modified: 2026-08-31T15:06:29.693

Link: CVE-2026-70713

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T10:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-284

    Improper Access Control