CVE-2026-70687: High severity Oracle Oracle E-Business Suite vulnerability
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs low-privileged access and network reachability to the Oracle Marketing Audience component over HTTP. No user interaction is required.
Which deployments are known to be affected?
Affected supported Oracle E-Business Suite versions are 12.2.3 through 12.2.15 where Oracle Marketing's Audience component is present.
What is the potential impact of successful exploitation?
An attacker may gain unauthorized access to critical data or complete access to data accessible through Oracle Marketing. The scope can extend beyond Oracle Marketing and significantly affect additional products.