Description
Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demand Planning. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data as well as unauthorized update, insert or delete access to some of Oracle Demand Planning accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-08-18
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Demand Planning is vulnerable to an unauthenticated HTTP-based attack that allows an attacker to read, update, insert, or delete data exposed by the application, driven by weaknesses in authentication and access control. This flaw provides unchecked access to critical supply‑chain information, resulting in confidentiality and integrity impacts as captured by a CVSS 3.1 Base Score of 8.2.

Affected Systems

The vulnerability affects Oracle Demand Planning released by Oracle Corporation, specifically versions 12.1 and 12.2. It is located within the internal operations component of the product and applies to any deployment that exposes the web interface to network traffic.

Risk and Exploitability

This flaw is highly exploitable because it requires no privileges, no user interaction, and low complexity. An adversary with network access to the HTTP interface can exploit it directly. The EPSS score is < 1% and the CVE is not listed in the CISA KEV catalog, yet the combination of high CVSS scoring and open exposure means that it should be treated with high urgency, especially for systems reachable from untrusted networks.

Generated by OpenCVE AI on August 21, 2026 at 07:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Demand Planning patch that addresses CVE-2026-70852 for versions 12.1 and 12.2.
  • If a patch is not yet available, restrict inbound HTTP traffic to Demand Planning by implementing network segmentation or firewall rules that allow connections only from trusted internal networks.
  • Enable detailed logging for the internal operations component and continuously monitor for unauthorized read or write attempts to Demand Planning data.

Generated by OpenCVE AI on August 21, 2026 at 07:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Full Data Compromise in Oracle Demand Planning
Weaknesses CWE-284
CWE-285

Fri, 21 Aug 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Manipulation in Oracle Demand Planning
Weaknesses CWE-284
CWE-306

Wed, 19 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Access Enables Unauthorized Data Manipulation in Oracle Demand Planning
Weaknesses CWE-284
CWE-306

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Demand Planning. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Demand Planning accessible data as well as unauthorized update, insert or delete access to some of Oracle Demand Planning accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle demand Planning
CPEs cpe:2.3:a:oracle:demand_planning:12.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:demand_planning:12.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle demand Planning
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Demand Planning
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T14:21:40.548Z

Reserved: 2026-08-04T22:06:34.601Z

Link: CVE-2026-70852

cve-icon Vulnrichment

Updated: 2026-08-24T13:30:15.715Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-18T21:17:41.210

Modified: 2026-08-24T15:16:43.337

Link: CVE-2026-70852

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T07:15:11Z

Weaknesses