Description
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework. While the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Autonomous Health Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Autonomous Health Framework accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Autonomous Health Framework’s Trace File Analyzer component contains a remotely exploitable flaw that allows attackers with network access over HTTP and low privileges to gain unauthorized access to critical data and, in some cases, to modify or delete that data. The vulnerability was evaluated with a CVSS 3.1 base score of 8.5, indicating significant confidentiality and integrity impacts and a revoked scope change.

Affected Systems

Oracle Corporation’s Autonomous Health Framework is affected. The vulnerability applies to releases 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, and 26.5.2. No other products are listed as affected in the official CVE data.

Risk and Exploitability

Because the flaw is accessible over the network with only low‑privilege credentials, it is easily exploitable by attackers who can reach the HTTP endpoint. The EPSS score indicates a very low exploitation probability (< 1%) and the issue is not listed in CISA’s KEV catalog, but its high CVSS score and potential scope expansion make it a high‑risk threat that should be addressed promptly.

Generated by OpenCVE AI on August 21, 2026 at 09:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued patch that removes the vulnerable Trace File Analyzer path or upgrade to a later version as recommended in Oracle’s security alert.
  • Block HTTP access to the Autonomous Health Framework endpoint for untrusted networks, limiting exposure to only trusted IP ranges.
  • Enforce the principle of least privilege by ensuring that service accounts used by Autonomous Health Framework have only the permissions required for operation and removing any unnecessary privileges.

Generated by OpenCVE AI on August 21, 2026 at 09:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Title Remote Low-Privilege HTTP Exploit in Oracle Autonomous Health Framework Trace File Analyzer Allows Data Access
Weaknesses CWE-284
CWE-862

Fri, 21 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Remote Access Vulnerability in Oracle Autonomous Health Framework Trace File Analyzer
Weaknesses CWE-284
CWE-862

Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Remote Access Vulnerability in Oracle Autonomous Health Framework Trace File Analyzer
Weaknesses CWE-284
CWE-862

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework. While the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Autonomous Health Framework accessible data as well as unauthorized update, insert or delete access to some of Oracle Autonomous Health Framework accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle autonomous Health Framework
CPEs cpe:2.3:a:oracle:autonomous_health_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.3.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.5.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.5.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle autonomous Health Framework
References
Metrics cvssV3_1

{'score': 8.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Autonomous Health Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:10:58.103Z

Reserved: 2026-08-04T22:06:34.593Z

Link: CVE-2026-70728

cve-icon Vulnrichment

Updated: 2026-08-25T15:00:37.329Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:25.370

Modified: 2026-08-26T20:18:03.747

Link: CVE-2026-70728

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T09:30:09Z

Weaknesses