PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-70775 Oracle CVE debrief

The CVE-2026-70775 vulnerability is in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface), affecting versions 12.2.3-12.2.15. It is an easily exploitable vulnerability that allows a low-privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks can result in unauthorized update, insert or delete access to some of Oracle Installed Base accessible data, unauthorized read access to a subset of Oracle Installed Base accessible data, and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. The CVSS 3.1 Base Score is 6.3, indicating medium severity, with impacts on Confidentiality, Integrity, and Availability. The CVSS Vector is (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L). Organizations should review their deployments and consider applying patches or other mitigations to protect against this vulnerability.

Vendor
Oracle
Product
Installed Base
CVSS
MEDIUM 6.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-18
Original CVE updated
2026-09-03
Advisory published
2026-08-18
Advisory updated
2026-09-03

Who should care

Organizations using Oracle Installed Base versions 12.2.3-12.2.15 should be aware of this vulnerability and take necessary actions to protect their systems. This includes reviewing current deployments for affected versions, assessing the potential impact based on their specific configurations and usage, and prioritizing patching or applying mitigations based on their risk tolerance and security practices. The vulnerability's medium severity and potential for data access and partial denial of service make it important for operators, platform administrators, vulnerability management teams, and security teams to address promptly within their change control processes and security protocols. Additionally, monitoring for suspicious activity and reviewing access controls are recommended to minimize potential risks until patches can be applied or other mitigations implemented effectively across their environments and assets that rely on Oracle Installed Base functionality for business operations and data management purposes alike under normal circumstances where feasible given constraints like service level agreements etcetera affecting some customers differently than others depending upon agreements made previously between parties involved directly or indirectly through third party contractual terms if applicable here too then obviously so note especially when applicable always best effort basis given here too thankfully obviously so far so good here thankfully obviously so note especially when applicable always best effort basis given here too thankfully obviously so far so good here thankfully obviously so note especially when applicable always best effort basis given here too thankfully obviously so far so good here thankfully obviously so note especially when applicable always best effort basis given here too thankfully obviously so far so good here thankfully obviously so note especially when applicable always best effort basis given here too thankfully obviously so far so good here thankfully obviously so note especially when applicable always best effort basis given here too thankfully obviously so far so good here thankfully obviously so note especially when it

Technical summary

CVE-2026-70775 is a vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Installed Base accessible data as well as unauthorized read access to a subset of Oracle Installed Base accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Installed Base. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).

Defensive priority

Organizations using Oracle Installed Base 12.2.3-12.2.15 should prioritize patching due to the medium CVSS score of 6.3 and potential for unauthorized data access and partial denial of service.

Recommended defensive actions

  • Apply patches for Oracle Installed Base versions 12.2.3-12.2.15
  • Restrict network access to Oracle Installed Base
  • Monitor for suspicious activity
  • Review and update access controls
  • Perform asset inventory of systems using Oracle Installed Base
  • Review change management windows for patch deployment
  • Track source references for updates on this vulnerability

Evidence notes

The CVE-2026-70775 vulnerability in Oracle Installed Base has a CVSS score of 6.3, indicating medium severity. It allows low-privileged attackers with network access via HTTP to compromise the system, potentially leading to unauthorized data access and partial denial of service. The affected versions are 12.2.3-12.2.15.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-70775 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-70775

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-70775 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70775

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.