PatchSiren

Oracle Corporation CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-73908

CVE-2026-73908 is a high-severity vulnerability in the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component. The vulnerability has a CVSS 3.1 Base Score of 7.5 and can be exploited by unauthenticated attackers with network access via HTTP, potentially leading to unauthorized access to critical data. The affected version is Helidon 4.5.0. Organizations should rev [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-73902

The CVE-2026-73902 vulnerability is an easily exploitable issue in the Imperative Web Server component of Helidon, a product of Oracle Fusion Middleware. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Helidon, potentially causing a hang or frequently repeatable crash, which constitutes a denial of service (DOS) attack. The affected version is Helidon 3.2.19. [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-73893

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:21.870Z and has not been modified since then. The CVE-2026-73893 vulnerability affects the Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component. The supported version that is affected is 4.5.0. This vulnerability is easily exploitable and allows an u [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-73892

The CVE-2026-73892 vulnerability affects the Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component in version 4.5.0. This vulnerability is classified as easily exploitable, allowing unauthenticated attackers with network access via HTTP to compromise Helidon. The potential impact includes unauthorized update, insert, or delete access to some of Helidon accessible da [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-71152

The CVE-2026-71152 vulnerability affects the Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component. This vulnerability is classified as critical with a CVSS score of 9.8, allowing unauthenticated attackers with network access via HTTP to compromise Helidon, potentially leading to a complete takeover. The vulnerability has been publicly disclosed and users of Helidon [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-71067

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:06.660Z and has not been modified since then. This vulnerability affects Oracle Agile PLM MCAD Connector version 3.6, and defenders should focus on verifying the affected product deployments and applying necessary patches or mitigations to prevent exploitation. The CVE record and official a [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-71065

The CVE-2026-71065 vulnerability affects Helidon version 3.2.18, a component of Oracle Fusion Middleware. This critical vulnerability, with a CVSS score of 9.3, allows unauthenticated attackers with network access via HTTP to compromise Helidon. The vulnerability has a high impact on confidentiality and integrity. Successful attacks can result in unauthorized access to critical data or complete access to [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-71036

CVE-2026-71036 is a critical vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0, classified as a high-severity issue. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise the product, potentially leading to unauthorized creation, deletion, or modification of critical data. Organizations should prioritize patching due to the c [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-71018

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:01.217Z and has not been modified since then. The CVE-2026-71018 vulnerability affects Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0, allowing easily exploitable attacks via HTTP. This vulnerability has a high CVSS score of 8.2, indicating significant confidentia [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-71016

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:00.987Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. The vulnerability (CVE-2026-71016) is in the Endeca Application Controller component of Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0. It is an easily exploitable vulner [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-71014

CVE-2026-71014 is a critical vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager 11.4.0, allowing unauthenticated attackers with network access via HTTP to compromise the system. This could lead to unauthorized creation, deletion, or modification of critical data. The CVSS score of 9.1 indicates high severity. Organizations should prioritize patching and verify system integrity.

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-71013

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:18:00.653Z and has not been modified since then. The CVE-2026-71013 vulnerability affects Oracle Hyperion Financial Management 11.2.25.0.000, classified under the Security component. This vulnerability allows a high privileged attacker with logon access to compromise the system, potentially le [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70990

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:57.980Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. The vulnerability in Oracle Commerce Guided Search / Oracle Commerce Experience Manager affects organizations using these products, particularly those with high-security requirements or sensitive d [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-70979

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:56.710Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. The CVE-2026-70979 vulnerability is a critical issue in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. It is an easily exploitable vulnerability that allows unau [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-70978

The CVE-2026-70978 vulnerability is a critical security issue in Oracle Commerce Guided Search / Oracle Commerce Experience Manager version 11.4.0. This vulnerability allows unauthenticated attackers with network access via HTTP to compromise the system, potentially leading to unauthorized creation, deletion, or modification of critical data. The CVSS score of 9.1 indicates a high severity vulnerability. [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70975

CVE-2026-70975 is a vulnerability in the Oracle Hyperion Financial Management product, specifically in the Security component. The affected version is 11.2.25.0.000. This vulnerability is easily exploitable by a low-privileged attacker with network access via HTTP, potentially leading to unauthorized access to critical data. Organizations should review and apply Oracle's security patches for Hyperion Fina [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70974

The CVE-2026-70974 vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000 is a medium-severity issue that allows low-privileged attackers with network access via HTTP to compromise the system and access critical data. This vulnerability is difficult to exploit and has a CVSS score of 5.3. Organizations should be aware of this vulnerability and take steps to mitigate it. The CVE record was pub [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70973

A high-severity vulnerability (CVE-2026-70973) exists in Oracle Hyperion Infrastructure Technology 11.2.25.0.000. This difficult-to-exploit vulnerability allows low-privileged attackers with network access via HTTP to potentially compromise the system. Successful attacks can result in takeover of Oracle Hyperion Infrastructure Technology. The CVSS 3.1 score is 7.5, indicating high severity. Organizations [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70960

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:54.503Z and has not been modified since then. The vulnerability in Oracle Hyperion Financial Management, a component of Oracle Hyperion, is classified under security and affects version 11.2.25.0.000. This vulnerability allows a low-privileged attacker with network access via HTTP to compro [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70959

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:54.387Z and has not been modified since then. The CVE-2026-70959 vulnerability is in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerabilit [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-70958

The CVE-2026-70958 vulnerability is a critical issue in Oracle Hyperion Infrastructure Technology, allowing unauthenticated attackers with network access via HTTP to compromise the system. The vulnerability has a CVSS score of 9.6 and requires human interaction to be exploited. Successful attacks can result in takeover of the system and may significantly impact additional products. The vulnerability is ex [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70956

The CVE-2026-70956 vulnerability affects Oracle Hyperion Infrastructure Technology version 11.2.25.0.000, an easily exploitable vulnerability allowing low-privileged attackers with network access via HTTP to compromise the technology, potentially leading to takeover. Organizations should prioritize patching or mitigating this vulnerability to prevent potential security breaches. The CVSS 3.1 Base Score is [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70955

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:53.840Z and has not been modified since then. The vulnerability, CVE-2026-70955, is a high-severity issue in Oracle Commerce Platform 11.4.0, with a CVSS 3.1 score of 7.5. It allows unauthenticated attackers with access to the physical communication segment to potentially compromise and tak [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-70954

The CVE-2026-70954 vulnerability affects Oracle Commerce Platform version 11.4.0, allowing unauthenticated attackers with network access via HTTP to compromise the platform. This critical vulnerability has a CVSS score of 9.8, impacting Confidentiality, Integrity, and Availability. Organizations should prioritize remediation efforts due to the potential for takeover of the platform. The CVE record was pub [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-70953

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:53.607Z and has not been modified since then. The CVE-2026-70953 vulnerability affects Oracle Commerce Platform version 11.4.0, allowing unauthenticated attackers with network access via TCP to compromise the platform. Successful attacks can result in takeover of Oracle Commerce Platform. T [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70943

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:52.463Z and has not been modified since then. This vulnerability affects Oracle Hyperion Financial Management version 11.2.25.0.000, specifically within the Security component. The vulnerability allows an unauthenticated attacker with access to the physical communication segment to compromi [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70942

CVE-2026-70942 is a high-severity vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000, classified under the Security component. The vulnerability allows low-privileged attackers with network access via HTTP to compromise the product, potentially impacting additional products. Successful attacks can result in unauthorized access to critical data. The CVE record was published on 2026-08-18T2 [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70941

The CVE-2026-70941 vulnerability affects Oracle Payroll versions 12.2.3-12.2.15, allowing low-privileged attackers with logon access to compromise the system. This vulnerability is classified as easily exploitable and has a high CVSS score of 8.8, indicating high severity. Successful attacks can result in takeover of Oracle Payroll and potentially impact additional products. The vulnerability has a high i [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70940

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:52.113Z and has not been modified since then. The vulnerability in Oracle Hyperion Financial Management (component: Security) allows a low-privileged attacker with network access via HTTP to compromise the system, potentially leading to takeover. The CVSS 3.1 Base Score is 8.8, indicating h [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70938

The CVE-2026-70938 vulnerability affects Oracle Hyperion Financial Management, specifically version 11.2.25.0.000, and is classified under the Security component. This vulnerability is exploitable by low-privileged attackers with network access via HTTP, potentially leading to unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. The CVSS 3.1 [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70937

The CVE-2026-70937 vulnerability affects Oracle Hyperion Financial Management 11.2.25.0.000, a product within Oracle Hyperion. This is a difficult-to-exploit vulnerability that allows low-privileged attackers with network access via HTTP to potentially take over Oracle Hyperion Financial Management. The vulnerability has a CVSS score of 7.5, indicating high severity with impacts on Confidentiality, Integr [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70936

The CVE-2026-70936 vulnerability affects Oracle Hyperion Financial Management, specifically the Security component. This vulnerability has a CVSS 3.1 Base Score of 7.1, indicating high severity due to its impact on confidentiality and integrity. The vulnerability is easily exploitable by low-privileged attackers with logon access, potentially leading to unauthorized creation, deletion, or modification of [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70932

The CVE-2026-70932 vulnerability affects the Oracle Order Management product in Oracle E-Business Suite (component: Product Diagnostic Tools) versions 12.2.3-12.2.15. This difficult-to-exploit vulnerability allows high privileged attackers with logon access to the infrastructure where Oracle Order Management executes to compromise Oracle Order Management. Successful attacks can result in unauthorized crea [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70931

CVE-2026-70931 is a high-severity vulnerability in Oracle Workflow, a component of Oracle E-Business Suite. The vulnerability, classified as easily exploitable, allows low-privileged attackers with network access via HTTP to compromise Oracle Workflow. This could lead to unauthorized creation, deletion, or modification of critical data and unauthorized ability to cause a hang or frequently repeatable cras [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70930

The CVE-2026-70930 vulnerability in Oracle Order Management, a component of Oracle E-Business Suite, is a difficult-to-exploit vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can result in the takeover of Oracle Order Management. The vulnerability has a high CVSS score of 7.5, indicating a serious security risk. Oracle Order Man [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70929

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:50.863Z and has not been modified since then. This vulnerability affects Oracle Hyperion Financial Management, specifically version 11.2.25.0.000, and allows a low-privileged attacker with network access via HTTP to compromise the system. Successful attacks can lead to unauthorized creation [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70927

CVE-2026-70927 is a vulnerability in Oracle Workflow, a component of Oracle E-Business Suite. The vulnerability allows unauthenticated attackers with network access via HTTP to compromise Oracle Workflow, potentially causing a hang or frequently repeatable crash (complete DOS) of Oracle Workflow. Organizations should review their deployments and consider patching due to the high CVSS score of 7.5. The CVE [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-70926

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:50.510Z and has not been modified since then. The vulnerability affects Oracle Workflow, a component of Oracle E-Business Suite, and has a CVSS score of 9.8, indicating critical severity. The vulnerability allows an unauthenticated attacker with network access via SMTP to compromise Oracle [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70923

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:50.163Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This vulnerability affects the Helidon product of Oracle Fusion Middleware, specifically the Imperative Web Server component, in version 3.2.19. It is an easily exploitable issue that allows unauth [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-70921

The CVE-2026-70921 vulnerability is a critical issue in Oracle Hyperion Financial Management, a product used for financial planning and analysis. This vulnerability falls under the category of security vulnerabilities and has a high likelihood of operational impact. The source confidence is limited, and the review context suggests that organizations should prioritize patching. The CVE record was published [truncated]

CRITICAL Oracle Corporation CVE published 2026-08-18

CVE-2026-70920

CVE-2026-70920 is a critical vulnerability in the Security component of Oracle Hyperion Financial Management, affecting version 11.2.25.0.000. The vulnerability allows a low-privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management, potentially impacting additional products. Oracle Hyperion Financial Management users and administrators should prioritize patching du [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70918

The CVE-2026-70918 vulnerability affects Oracle Product Hub, a component of Oracle E-Business Suite, specifically in the Outbound Data module. This vulnerability is easily exploitable by low-privileged attackers with network access via HTTP, potentially leading to a complete takeover of the Oracle Product Hub. The CVSS score of 8.8 indicates high severity, impacting confidentiality, integrity, and availab [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70917

CVE-2026-70917 is a medium-severity vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000. The vulnerability allows an unauthenticated attacker with logon to the infrastructure to compromise Oracle Hyperion Financial Management, resulting in unauthorized read access to a subset of accessible data. The CVSS 3.1 Base Score is 4.0, with a vector of CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N. [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70916

The CVE-2026-70916 vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000 is an easily exploitable issue that allows unauthenticated attackers with logon access to the infrastructure to compromise the product. Successful attacks can result in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. The CVSS 3.1 Base Score is 4.0, indicating a medium severi [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70914

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:49.223Z and has not been modified since then. The vulnerability in Oracle Hyperion Financial Management 11.2.25.0.000 allows unauthenticated attackers with logon to the infrastructure to potentially take over the system with human interaction. The vulnerability has a CVSS score of 7.0 and a [truncated]

MEDIUM Oracle Corporation CVE published 2026-08-18

CVE-2026-70911

A vulnerability in Oracle Hyperion Financial Management allows an unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management, potentially resulting in unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. The CVE record was published on 2026-08-18T21:17:48.990Z and has not been modified since then. Organizations should r [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70908

CVE-2026-70908 is a vulnerability in the Helidon product of Oracle Fusion Middleware, specifically in the Imperative Web Server component. The supported version affected is 3.2.18. This vulnerability is easily exploitable by unauthenticated attackers with network access via HTTP, potentially leading to unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. The CVSS [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70904

The CVE-2026-70904 vulnerability affects the Oracle Hyperion Data Relationship Management product, specifically version 11.2.25.0.000. This vulnerability is classified as a high-severity issue, with a CVSS 3.1 Base Score of 8.1, indicating a high impact on confidentiality and integrity. The vulnerability allows an unauthenticated attacker with access to the physical communication segment to compromise the [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70903

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:48.050Z and has not been modified since then. The CVE-2026-70903 vulnerability affects Oracle Hyperion Data Relationship Management, version 11.2.25.0.000, and allows low-privileged attackers with network access via HTTPS to compromise the product. Successful attacks require human interacti [truncated]

HIGH Oracle Corporation CVE published 2026-08-18

CVE-2026-70902

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T21:17:47.933Z and has not been modified since then. The CVE-2026-70902 vulnerability affects Oracle Hyperion Data Relationship Management product, specifically version 11.2.25.0.000. The vulnerability allows a low-privileged attacker with logon to the infrastructure to compromise the product, pot [truncated]