Description
Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).
Published: 2026-08-18
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Trace File Analyzer component of Oracle Autonomous Health Framework and allows an attacker with local high‑privilege access, who can co‑operate with a third‑party user to trigger the vulnerable functionality, to create, modify, or delete critical data and to cause the framework to hang or crash repeatedly, thereby compromising both integrity and availability.

Affected Systems

Oracle Autonomous Health Framework deployments running the following versions are affected: 26-26.1.0, 26.2.0, 26.3.1, 26.5.0, and 26.5.2. These releases contain the vulnerable Trace File Analyzer component.

Risk and Exploitability

The CVSS v3.1 base score of 7.4 reflects significant integrity and availability impact and the vector (AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H) indicates the attack originates locally with low complexity, high‑privileged users, and requires a user interaction from a non‑attacking third party. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. However, because the scope shift allows potential control over other Oracle products on the same infrastructure, any environment where high‑privileged local accounts exist is still a valid target for this local exploit.

Generated by OpenCVE AI on August 25, 2026 at 21:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Autonomous Health Framework patch that removes or fixes the vulnerable Trace File Analyzer component (any release newer than 26.5.2).
  • Restrict local accounts with elevated privileges to the smallest set of administrators required to run the framework, and audit those accounts for suspicious activity.
  • Limit or disable user‑initiated actions that can trigger the Trace File Analyzer if the framework’s configuration allows such control, or quarantine the component until a vendor patch is available.
  • Implement monitoring of the framework’s trace directories for unexpected file creation, deletion, or frequent crashes, and alert on anomalies.
  • Regularly check Oracle’s security updates portal and authoritative advisories for new patches or additional mitigations.

Generated by OpenCVE AI on August 25, 2026 at 21:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local High‑Privilege Exploit of Oracle Autonomous Health Framework Trace File Analyzer

Tue, 25 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Local High-Privilege Attack via Trace File Analyzer in Oracle Autonomous Health Framework
Weaknesses CWE-640
CWE-734

Tue, 25 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 21 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Local High-Privilege Attack via Trace File Analyzer in Oracle Autonomous Health Framework
Weaknesses CWE-640
CWE-734

Fri, 21 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Trace File Analyzer Enables Unauthorized Modification and Denial of Service
Weaknesses CWE-264
CWE-284

Wed, 19 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Trace File Analyzer Enables Unauthorized Modification and Denial of Service
Weaknesses CWE-264
CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and 26.5.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Autonomous Health Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Autonomous Health Framework accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 7.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H).
First Time appeared Oracle
Oracle autonomous Health Framework
CPEs cpe:2.3:a:oracle:autonomous_health_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.3.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.5.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:autonomous_health_framework:26.5.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle autonomous Health Framework
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:N/I:H/A:H'}


Subscriptions

Oracle Autonomous Health Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-25T15:10:23.086Z

Reserved: 2026-08-04T22:06:34.593Z

Link: CVE-2026-70734

cve-icon Vulnrichment

Updated: 2026-08-25T15:00:43.978Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:26.087

Modified: 2026-08-26T20:17:36.590

Link: CVE-2026-70734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T21:30:06Z

Weaknesses