Description
Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Call Center Technology product contains a vulnerability that permits an unauthenticated attacker with network access via HTTP to compromise the system. The flaw is an improper authorization (CWE-284). An attacker can execute the vulnerability to gain control and potentially take over the entire application. This results in full disclosure of confidential data, modification of data, and denial of legitimate availability.

Affected Systems

The affected product is Oracle Call Center Technology (part of Oracle E‑Business Suite) in versions 12.2.3 through 12.2.15. All deployments running any of these versions are susceptible if they are reachable over HTTP.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 indicates high severity, with full confidentiality, integrity, and availability impacts. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not currently listed in CISA's KEV catalogue. Based on the description the attack vector is network access through HTTP. The lack of authentication requirement means any host that can reach the HTTP endpoint could exploit the flaw, making the risk significant for exposed deployments.

Generated by OpenCVE AI on August 25, 2026 at 00:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses the vulnerability for versions 12.2.3 to 12.2.15.
  • Restrict HTTP access to the Oracle Call Center Technology servers by configuring firewall rules to allow traffic only from approved hosts.
  • Enable logging and intrusion detection to monitor for abnormal HTTP requests and alert on suspicious activity.

Generated by OpenCVE AI on August 25, 2026 at 00:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle e-business Suite
CPEs cpe:2.3:a:oracle:e-business_suite:*:*:*:*:*:*:*:*
Vendors & Products Oracle e-business Suite

Tue, 25 Aug 2026 00:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Attack Compromise Oracle Call Center Technology

Mon, 24 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Remote Compromise of Oracle Call Center Technology
Weaknesses CWE-306

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Allows Remote Compromise of Oracle Call Center Technology
Weaknesses CWE-306

Fri, 21 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploitation Allowing Takeover of Oracle Call Center Technology
Weaknesses CWE-284

Wed, 19 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploitation Allowing Takeover of Oracle Call Center Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle call Center Technology
CPEs cpe:2.3:a:oracle:call_center_technology:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle call Center Technology
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Call Center Technology E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:21:58.441Z

Reserved: 2026-08-04T22:06:34.599Z

Link: CVE-2026-70814

cve-icon Vulnrichment

Updated: 2026-08-24T15:12:45.514Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:36.067

Modified: 2026-08-27T18:31:15.107

Link: CVE-2026-70814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T00:15:04Z

Weaknesses