CVE-2026-70689: Critical severity Oracle Oracle Essbase vulnerability
Vulnerability in Oracle Essbase (component: Infrastructure). The supported version that is affected is 21.8.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Essbase. Successful attacks of this vulnerability can result in takeover of Oracle Essbase. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Oracle Essbase deployments running the affected supported version, 21.8.1.0.0, are exposed if an attacker can reach the product over HTTP. The attack requires no authentication or user interaction.
What level of access does an attacker need to exploit it?
An attacker needs network access to Oracle Essbase through HTTP. No privileges or prior account are required, and exploitation is described as easy.
What could happen if exploitation succeeds?
Successful exploitation can result in takeover of Oracle Essbase. Confidentiality, integrity, and availability can all be fully impacted.