File Transmission Vulnerability in Oracle E-Business Suite Payments
CVE-2026-70699

7.4HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70699?

A vulnerability exists in the File Transmission component of the Oracle Payments product within the Oracle E-Business Suite, specifically affecting versions 12.2.3 to 12.2.15. This vulnerability allows unauthenticated attackers with network access to HTTPS to potentially exploit the system. If successfully exploited, an attacker could create, delete, or modify access to critical data, risking unauthorized access to all Oracle Payments data. Organizations using affected versions should take immediate action to mitigate these risks.

Affected Version(s)

Oracle Payments 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.