Description
Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data as well as unauthorized update, insert or delete access to some of Oracle General Ledger accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle General Ledger. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
Published: 2026-08-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle General Ledger’s internal operations component enables a low‑privileged user with network access via HTTP to gain unauthorized read, write, or delete access to critical general ledger data and to trigger a partial denial of service. The weakness stems from improper access controls and lack of proper authorization enforcement, allowing the attacker to compromise the confidentiality, integrity and availability of the ledger.

Affected Systems

Vulnerable versions of Oracle General Ledger in Oracle E‑Business Suite, from 12.2.3 through 12.2.15, are affected. The issue resides in the internal operations component and can be exploited over the network through HTTP interfaces.

Risk and Exploitability

The CVSS 3.1 base score of 7.6 indicates a high severity. No EPSS data is available, so the current exploitation likelihood is unknown, but the vulnerability is public and easily exploitable from any networked environment that can reach the HTTP endpoints. Because the attack relies on low privilege credentials, an attacker who can obtain such credentials is capable of compromising all accessible ledger data. The vulnerability is not listed in CISA’s KEV catalog, yet its high impact warrants immediate attention.

Generated by OpenCVE AI on August 19, 2026 at 12:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s security patch for CVE‑2026‑70764 as published in the August 2026 security alert.
  • Restrict HTTP access to the Oracle General Ledger application to a trusted internal network or via VPN only, limiting exposure to untrusted hosts.
  • Review and tighten role‑based access controls to enforce least privilege, ensuring that users do not possess unnecessary update, insert or delete rights on ledger data.
  • If a patch is not immediately available, temporarily disable the vulnerable internal operations endpoint or block its HTTP ports until the fix can be deployed.

Generated by OpenCVE AI on August 19, 2026 at 12:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Access Enables Unauthorized Ledger Manipulation and Partial Denial of Service
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle General Ledger product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle General Ledger. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle General Ledger accessible data as well as unauthorized update, insert or delete access to some of Oracle General Ledger accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle General Ledger. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).
First Time appeared Oracle
Oracle general Ledger
CPEs cpe:2.3:a:oracle:general_ledger:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle general Ledger
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L'}


Subscriptions

Oracle General Ledger
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-19T12:55:13.177Z

Reserved: 2026-08-04T22:06:34.595Z

Link: CVE-2026-70764

cve-icon Vulnrichment

Updated: 2026-08-19T12:11:31.502Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:29.060

Modified: 2026-08-25T17:46:57.273

Link: CVE-2026-70764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T12:30:04Z

Weaknesses