Description
Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle E-Business Tax executes to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle E-Business Tax. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in the internal operations component of Oracle E‑Business Tax. A user who can log on to the underlying infrastructure but does not have privileged application rights can create, delete or modify tax data that is critical to business operations and can also force the application to crash, resulting in a denial‑of‑service condition. The weakness is an improper access control and improper privilege management flaw.

Affected Systems

Oracle E‑Business Tax versions 12.2.3 through 12.2.15 are affected. The flaw is limited to the internal operations functionality of this product; no other Oracle products are listed as impacted.

Risk and Exploitability

The CVSS score of 7.1 indicates high integrity and availability impact. The attack vector is local, as implied by the CVSS vector AV:L, so a malicious actor only needs infrastructure log‑on credentials. Because the EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, it may not yet be widely exploited, but environments where infrastructure users have broad access remain at significant risk.

Generated by OpenCVE AI on August 24, 2026 at 23:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the August 2026 security alert
  • Limit infrastructure log‑on privileges to only those users who truly need full access to Oracle E‑Business Tax
  • Implement monitoring of audit logs for unauthorized creation, deletion or modification of tax data
  • If possible, temporarily disable the internal operations feature until the patch lands

Generated by OpenCVE AI on August 24, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Exploitation in Oracle E‑Business Tax Internal Operations

Mon, 24 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Denial of Service in Oracle E‑Business Tax
Weaknesses CWE-269

Mon, 24 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation and Denial of Service in Oracle E‑Business Tax
Weaknesses CWE-269

Fri, 21 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Attack Compromises Oracle E‑Business Tax Data and Availability
Weaknesses CWE-284
CWE-285

Wed, 19 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege Attack Compromises Oracle E‑Business Tax Data and Availability
Weaknesses CWE-284
CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle E-Business Tax executes to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle E-Business Tax. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
First Time appeared Oracle
Oracle e-business Tax
CPEs cpe:2.3:a:oracle:e-business_tax:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle e-business Tax
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Oracle E-business Tax
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T16:14:54.235Z

Reserved: 2026-08-04T22:06:34.598Z

Link: CVE-2026-70806

cve-icon Vulnrichment

Updated: 2026-08-24T16:14:47.489Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:34.960

Modified: 2026-08-28T14:48:35.100

Link: CVE-2026-70806

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T00:00:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function