Vulnerability in Oracle Payments Product of Oracle E-Business Suite
CVE-2026-70694

7.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70694?

A vulnerability exists in the Oracle Payments component of the Oracle E-Business Suite, specifically between versions 12.2.3 and 12.2.15. This vulnerability allows attackers with high privileges and network access via HTTP to exploit the system. Although primarily affecting Oracle Payments, the consequences of exploitation could extend to other components within the Oracle E-Business Suite. Successful exploitation may enable unauthorized creations, deletions, or modifications of critical data, potentially jeopardizing the confidentiality and integrity of all accessible Oracle Payments data.

Affected Version(s)

Oracle Payments 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.