Vulnerability in Oracle Loans Product of Oracle E-Business Suite
CVE-2026-70845

7.1HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
18 August 2026

What is CVE-2026-70845?

A vulnerability exists in the Oracle Loans component of Oracle E-Business Suite, potentially allowing low-privileged attackers with HTTP network access to exploit the system. This exploitation can lead to unauthorized creation, deletion, or modification of critical data, affecting all accessible data within Oracle Loans. Additionally, there is a risk of causing a partial denial of service, impacting the system's availability. The supported versions from 12.2.3 to 12.2.15 are particularly vulnerable, warranting immediate attention.

Affected Version(s)

Oracle Loans 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.