Vulnerability in Oracle E-Business Suite's Purchasing Component
CVE-2026-70811
8.1HIGH
What is CVE-2026-70811?
An access control vulnerability exists in the Oracle Purchasing component of the Oracle E-Business Suite, affecting versions 12.2.5 through 12.2.15. This easily exploitable flaw allows attackers with minimal privileges and network access via HTTP to compromise the system. It can lead to unauthorized actions such as creating, deleting, or modifying critical data within the Oracle Purchasing module, resulting in significant risks to data confidentiality and integrity. The vulnerability necessitates immediate attention to safeguard sensitive information against potential threats.
Affected Version(s)
Oracle Purchasing 12.2.5 <= 12.2.15