CVE-2026-70845: High severity Oracle Oracle E-Business Suite (Oracle Loans) vulnerability
Vulnerability in the Oracle Loans product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Loans. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Loans accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Loans. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs network access to Oracle Loans over HTTP and low-privileged credentials. No user interaction is required.
Which deployments are affected?
Affected supported Oracle E-Business Suite Oracle Loans versions are 12.2.3 through 12.2.15. The issue is in the Internal Operations component.
What could a successful attacker do?
A successful attacker could create, delete, or modify critical data or all data accessible through Oracle Loans. They could also cause a partial denial of service for Oracle Loans.