CVE-2026-70922: High severity Oracle Oracle Financial Services Enterprise Case Management vulnerability
Vulnerability in the Oracle Financial Services Enterprise Case Management product of Oracle Financial Services Applications (component: Web UI). Supported versions that are affected are 8.0.8.2 and 8.1.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Case Management. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Enterprise Case Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs network access to the affected product's Web UI over HTTP and must have low-level privileges. No user interaction is required.
Which deployments are known to be affected?
The affected supported versions are 8.0.8.2 and 8.1.2.11 of Oracle Financial Services Enterprise Case Management.
What is the likely impact of successful exploitation?
Successful exploitation can lead to takeover of Oracle Financial Services Enterprise Case Management, with high confidentiality, integrity, and availability impact.