Description
Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Service Fulfillment Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Fulfillment Engine component of Oracle Service Fulfillment Manager, permitting an attacker with low privileges and network access via HTTP to compromise the system. The CVSS vector indicates a high confidentiality impact and a low integrity impact, and the weakness exposes critical data that could be read, updated, inserted, or deleted.

Affected Systems

Impact is limited to Oracle Corporation's Service Fulfillment Manager included in Oracle E‑Business Suite. Affected versions range from 12.2.3 through 12.2.15. While the vulnerability is tied to this product, the description notes that attacks may also affect other products within the Oracle suite due to the scope change.

Risk and Exploitability

The CVSS score of 7.6 classifies the flaw as high severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the flaw is not listed in the CISA KEV catalog. The attack vector is remote over the network, requiring HTTP access and a low‑privilege credential, with the vector implying the vulnerability can successfully be exploited with user interaction from a different person. Given the scope change, a compromise can lead to privilege escalation within the Service Fulfillment Manager environment.

Generated by OpenCVE AI on August 21, 2026 at 07:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the official Oracle patch for Service Fulfillment Manager versions 12.2.3 to 12.2.15.
  • Restrict HTTP access to trusted IP ranges or enforce VPN‑only connectivity for the Service Fulfillment Manager.
  • Verify and enforce role‑based access controls, audit privileges, and monitor for anomalous data modifications.

Generated by OpenCVE AI on August 21, 2026 at 07:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote HTTP Data Access in Oracle Service Fulfillment Manager
Weaknesses CWE-284
CWE-285

Fri, 21 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low Privilege HTTP Exploit in Oracle Service Fulfillment Manager
Weaknesses CWE-284
CWE-640

Wed, 19 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Low Privilege HTTP Exploit in Oracle Service Fulfillment Manager
Weaknesses CWE-284
CWE-640

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Service Fulfillment Manager product of Oracle E-Business Suite (component: Fulfillment Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Service Fulfillment Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Service Fulfillment Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Service Fulfillment Manager accessible data as well as unauthorized update, insert or delete access to some of Oracle Service Fulfillment Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle service Fulfillment Manager
CPEs cpe:2.3:a:oracle:service_fulfillment_manager:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle service Fulfillment Manager
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Service Fulfillment Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:23:30.682Z

Reserved: 2026-08-04T22:06:34.597Z

Link: CVE-2026-70786

cve-icon Vulnrichment

Updated: 2026-08-24T14:08:06.275Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:32.100

Modified: 2026-08-28T18:27:32.537

Link: CVE-2026-70786

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T08:00:08Z

Weaknesses