Description
Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Call Center Technology product contains a vulnerability that permits an unauthenticated attacker with network access via HTTP to compromise the system. An attacker can execute the vulnerability to gain control and potentially take over the entire application. This results in full disclosure of confidential data, modification of data, and denial of legitimate availability.

Affected Systems

The affected product is Oracle Call Center Technology (part of Oracle E‑Business Suite) in versions 12.2.3 through 12.2.15. All deployments running any of these versions are susceptible if they are reachable over HTTP.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 indicates high severity, with full confidentiality, integrity, and availability impacts. The EPSS is not available and the vulnerability is not currently listed in CISA's KEV catalogue. Based on the description the attack vector is network access through HTTP. The lack of authentication requirement means any host that can reach the HTTP endpoint could exploit the flaw, making the risk significant for exposed deployments.

Generated by OpenCVE AI on August 19, 2026 at 02:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch that addresses the vulnerability for versions 12.2.3 to 12.2.15.
  • Restrict HTTP access to the Oracle Call Center Technology servers by configuring firewall rules to allow traffic only from approved hosts.
  • Enable logging and intrusion detection to monitor for abnormal HTTP requests and alert on suspicious activity.

Generated by OpenCVE AI on August 19, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Remote Exploitation Allowing Takeover of Oracle Call Center Technology
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Call Center Technology. Successful attacks of this vulnerability can result in takeover of Oracle Call Center Technology. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle call Center Technology
CPEs cpe:2.3:a:oracle:call_center_technology:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle call Center Technology
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Call Center Technology
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:01:57.651Z

Reserved: 2026-08-04T22:06:34.599Z

Link: CVE-2026-70814

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:36.067

Modified: 2026-08-18T21:17:36.067

Link: CVE-2026-70814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T02:30:03Z

Weaknesses