Impact
CVE-2026-70774 describes a flaw in Oracle Warehouse Management that permits attackers with low privileges and network connectivity over HTTP to create, delete or alter data and trigger a partial denial of service. The weakness is an improper authorization control, allowing unauthorized use of privileged functions. This leads to loss of data integrity and limited availability disruption for the Warehouse Management application.
Affected Systems
Affected are Oracle Warehouse Management versions 12.2.3 through 12.2.15, as part of Oracle E‑Business Suite’s Internal Operations component. The vulnerability exists in all supported releases within that range.
Risk and Exploitability
The CVSS 3.1 base score of 7.1 indicates a moderate to high severity, with integral and availability impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires low privilege and remote network access via HTTP, making it relatively easy to exploit from any host that can reach the application. Once exploited, an attacker can change critical data and cause a partial denial of service.
OpenCVE Enrichment