CVE-2026-70806
Last modified
CVE-2026-70806 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
Vulnerability in the Oracle E-Business Tax product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle E-Business Tax executes to compromise Oracle E-Business Tax. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Tax accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle E-Business Tax. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Oracle | E-Business Tax | >= 12.2.3, <= 12.2.15 |
References
- https://www.oracle.com/security-alerts/cspuaug2026.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-70806?
How severe is CVE-2026-70806?
How do I fix CVE-2026-70806?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-70800Vulnerability in the Oracle SDP Number Portability product o…7.3
- CVE-2026-70801Vulnerability in the Oracle Flow Manufacturing product of Or…7.1
- CVE-2026-70802Vulnerability in the Oracle Public Sector Human Resources pr…8
- CVE-2026-70803Vulnerability in the Oracle General Ledger product of Oracle…7.6
- CVE-2026-70804Vulnerability in the Oracle Public Sector Human Resources pr…7.7
- CVE-2026-70805Vulnerability in the Oracle Project Planning and Control pro…8.1
- CVE-2026-70807Vulnerability in the Oracle Call Center Technology product o…8.5
- CVE-2026-70808Vulnerability in the Oracle Scripting product of Oracle E-Bu…7.1
- CVE-2026-70809Vulnerability in the Oracle Scripting product of Oracle E-Bu…7.1
- CVE-2026-7081A vulnerability was detected in Tenda F456 1.0.0.5. Affected…8.8
- CVE-2026-70810Vulnerability in the Oracle Scripting product of Oracle E-Bu…7.5
- CVE-2026-70811Vulnerability in the Oracle Purchasing product of Oracle E-B…8.1
Are you affected by CVE-2026-70806?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
