Remote Code Execution Vulnerability in Oracle Payments by Oracle
CVE-2026-70695

7.7HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70695?

A vulnerability exists in the Oracle Payments component of the Oracle E-Business Suite which allows an attacker with network access via HTTP to compromise the system. This flaw could lead to unauthorized creation, deletion, or modification of critical data, including all Oracle Payments accessible data. An attacker could gain full control over sensitive data, thereby affecting not only Oracle Payments but potentially other connected systems as well.

Affected Version(s)

Oracle Payments 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.