Description
Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Management executes to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Order Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).
Published: 2026-08-18
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A privilege escalation flaw in the Product Diagnostic Tools component of Oracle Order Management allows an attacker who has high‑privileged logon access to the underlying infrastructure to compromise the application and gain unauthorized creation, deletion, or modification of critical data. The vulnerability does not require user interaction and can be abused locally by users with elevated privileges, resulting in confidentiality and integrity breaches.

Affected Systems

Affected versions are Oracle Order Management 12.2.3 through 12.2.15, part of Oracle E‑Business Suite. The flaw exists within the Order Management application and can also lead to compromise of other integrated products due to scope change.

Risk and Exploitability

The CVSS score of 7.2 reflects a high severity of confidentiality and integrity impact. The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. Because the attack vector is local and requires high privileges, the risk is primarily to internal users who have the necessary access. Organizational stakeholders should treat this as an urgent patch requirement, as a successful exploit grants the attacker destructive capabilities over all data accessible to Order Management.

Generated by OpenCVE AI on August 21, 2026 at 04:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Order Management patch that addresses CVE-2026-70932
  • Restrict access to the diagnostic tools and enforce least‑privilege principals
  • Disable or limit the diagnostic functionality if it is not required for operations

Generated by OpenCVE AI on August 21, 2026 at 04:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle Order Management Product Diagnostic Tools
Weaknesses CWE-284
CWE-285

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
Title Oracle Order Management Privilege Escalation via Diagnostic Tools
Weaknesses CWE-284
CWE-360

Wed, 19 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Title Oracle Order Management Privilege Escalation via Diagnostic Tools
Weaknesses CWE-284
CWE-360

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Order Management executes to compromise Oracle Order Management. While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Order Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).
First Time appeared Oracle
Oracle order Management
CPEs cpe:2.3:a:oracle:order_management:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle order Management
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N'}


Subscriptions

Oracle Order Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-22T02:50:29.453Z

Reserved: 2026-08-04T22:06:34.606Z

Link: CVE-2026-70932

cve-icon Vulnrichment

Updated: 2026-08-22T02:50:22.846Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:51.213

Modified: 2026-08-28T14:44:06.930

Link: CVE-2026-70932

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T04:15:04Z

Weaknesses