Description
Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Public Sector Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Public Sector Human Resources contains a flaw in its regression‑testing component that allows a high‑privileged attacker who can reach the application over HTTP to create, delete, or modify critical data. Based on the description, it is inferred that the vulnerability arises from an authorization failure, as it permits actions beyond the attacker’s authorized scope. This leads to unauthorized data modification and full access to all personnel records, exposing both confidentiality and integrity.

Affected Systems

Oracle Public Sector Human Resources version 12.2.3 through 12.2.15 is affected.

Risk and Exploitability

The CVSS v3.1 base score of 7.7 indicates significant confidentiality and integrity impact. Exploitation requires a high‑privileged user with network access over HTTP; the flaw is difficult to exploit and the EPSS score is <1%, indicating very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the scope change means a successful attack could affect other Oracle systems. The attacker could permanently alter data or authorize additional privileged actions within the application.

Generated by OpenCVE AI on August 21, 2026 at 09:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch or upgrade to a release that includes the fix (such as version 12.2.16 or newer).
  • Restrict HTTP access to the regression‑testing component to trusted IP addresses and enforce strict authentication for privileged users.
  • If the regression‑testing functionality is not required, disable or remove it to eliminate the attack surface.

Generated by OpenCVE AI on August 21, 2026 at 09:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Oracle Public Sector Human Resources Regression Testing Privilege Escalation and Data Modification Vulnerability
Weaknesses CWE-250
CWE-284

Fri, 21 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Public Sector Human Resources
Weaknesses CWE-284

Wed, 19 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via HTTP in Oracle Public Sector Human Resources
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Human Resources product of Oracle E-Business Suite (component: Regression Testing). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Human Resources. While the vulnerability is in Oracle Public Sector Human Resources, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Public Sector Human Resources accessible data as well as unauthorized access to critical data or complete access to all Oracle Public Sector Human Resources accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle public Sector Human Resources
CPEs cpe:2.3:a:oracle:public_sector_human_resources:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Human Resources
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Public Sector Human Resources
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T19:54:21.271Z

Reserved: 2026-08-04T22:06:34.598Z

Link: CVE-2026-70804

cve-icon Vulnrichment

Updated: 2026-08-24T19:49:39.682Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:34.667

Modified: 2026-08-28T17:34:18.637

Link: CVE-2026-70804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T21:00:03Z

Weaknesses
  • CWE-250

    Execution with Unnecessary Privileges

  • CWE-284

    Improper Access Control