Description
Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for EMEA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financials for EMEA accessible data as well as unauthorized update, insert or delete access to some of Oracle Financials for EMEA accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An easily exploitable flaw in the Oracle Financials for EMEA product of Oracle E‑Business Suite allows an attacker who is a low‑privileged user and has network reachability over HTTP to gain unauthorized access to critical data. The vulnerability can also allow the attacker to insert, update, or delete data that the user normally cannot reach, thereby undermining the integrity of the application’s data. The weakness results in confidentiality loss for sensitive records and potential manipulation of financial information.

Affected Systems

Oracle Corporation’s Oracle Financials for EMEA, part of the Oracle E‑Business Suite, internally scoped under the Internal Operations component. The affected releases span from version 12.2.3 through 12.2.15, meaning any installation of the product within this range is vulnerable.

Risk and Exploitability

The CVSS 3.1 base score of 7.1 indicates a high severity, with an attack vector over the network and low authentication required. The EPSS score of < 1% indicates a low, but non‑zero, probability of exploitation. Because the weakness is exploitable via a standard HTTP request, an attacker need only be able to reach the application, making it attractive in environments where this application is exposed to the internet or an untrusted internal network. The flaw is not currently listed in the CISA KEV catalog, but its impact and potential for compromise warrant immediate attention.

Generated by OpenCVE AI on August 21, 2026 at 06:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Security Alert for Aug 2026 to upgrade Oracle Financials for EMEA to a patched version (see the referenced Oracle alert link).
  • Restrict network access to the Oracle Financials for EMEA HTTP endpoints to trusted users or IP ranges, using firewall rules or VPNs to limit exposure.
  • Implement continuous monitoring of application logs for anomalous insert, update, or delete operations, and enforce strict role‑based access controls to safeguard sensitive financial transactions.

Generated by OpenCVE AI on August 21, 2026 at 06:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Allows Unauthorized Data Access and Modification in Oracle Financials for EMEA
Weaknesses CWE-284
CWE-639

Wed, 19 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification via HTTP in Oracle Financials for EMEA
Weaknesses CWE-284
CWE-639

Wed, 19 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Modification via HTTP in Oracle Financials for EMEA
Weaknesses CWE-284
CWE-639

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for EMEA. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financials for EMEA accessible data as well as unauthorized update, insert or delete access to some of Oracle Financials for EMEA accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle financials For Emea
CPEs cpe:2.3:a:oracle:financials_for_emea:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle financials For Emea
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Financials For Emea
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:22:45.969Z

Reserved: 2026-08-04T22:06:34.599Z

Link: CVE-2026-70816

cve-icon Vulnrichment

Updated: 2026-08-24T14:07:58.833Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:36.347

Modified: 2026-09-03T16:15:32.237

Link: CVE-2026-70816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T06:00:11Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-639

    Authorization Bypass Through User-Controlled Key