Description
Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Internal Operations component of Oracle Yard Management allows an attacker with network access via HTTP and low privileges to compromise the system. Successful exploitation can result in a full takeover, granting the attacker control over confidential, integrity, and availability aspects of the application. This exposure is documented with a CVSS 3.1 base score of 8.8, highlighting high impact.

Affected Systems

Affected product is Oracle Yard Management within Oracle E‑Business Suite. Oracle acknowledges versions 12.2.3 through 12.2.15 as impacted. The vulnerability is specific to the Yard Management module when accessed over HTTP.

Risk and Exploitability

The CVSS score of 8.8 places the flaw in the high severity range, and although EPSS data is not available, the description labels it as easily exploitable. The attack vector is network-based via HTTP, requiring only low-level privileges and no user interaction, which increases the likelihood of exploitation. The vulnerability is not yet listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 19, 2026 at 12:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Oracle patch that resolves the vulnerability for all affected versions of Yard Management.
  • Restrict HTTP access to the Yard Management interface to trusted internal networks or VPN endpoints, blocking unauthenticated public traffic.
  • Monitor authentication and audit logs for anomalous activities, and enforce strict least‑privilege practices for users accessing Yard Management.

Generated by OpenCVE AI on August 19, 2026 at 12:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
Title Oracle Yard Management Remote Exploitation Leads to Full System Takeover

Wed, 19 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Oracle Yard Management Remote Exploitation Leads to Full System Takeover
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Yard Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Yard Management. Successful attacks of this vulnerability can result in takeover of Oracle Yard Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle yard Management
CPEs cpe:2.3:a:oracle:yard_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle yard Management
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Yard Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:22:30.891Z

Reserved: 2026-08-04T22:06:34.597Z

Link: CVE-2026-70792

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:51.526Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:32.960

Modified: 2026-08-28T17:35:29.140

Link: CVE-2026-70792

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T06:15:16Z

Weaknesses