CVE-2026-70718 Overview
CVE-2026-70718 is a high-severity vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite, within the Internal Operations component. Supported versions 12.2.3 through 12.2.15 are affected. A low-privileged attacker with network access via HTTP can exploit the flaw, though exploitation is described as difficult. Successful attacks result in complete takeover of Oracle Bills of Material and, due to a scope change, may impact additional Oracle products. The vulnerability affects confidentiality, integrity, and availability. Oracle addressed the issue in its August 2026 Critical Patch Update.
Critical Impact
Successful exploitation allows full takeover of Oracle Bills of Material and can extend impact to additional Oracle E-Business Suite components through scope change.
Affected Products
- Oracle E-Business Suite — Oracle Bills of Material 12.2.3
- Oracle E-Business Suite — Oracle Bills of Material versions 12.2.4 through 12.2.14
- Oracle E-Business Suite — Oracle Bills of Material 12.2.15
Discovery Timeline
- 2026-08-18 - CVE-2026-70718 published to NVD
- 2026-08-20 - Last updated in NVD database
Technical Details for CVE-2026-70718
Vulnerability Analysis
The flaw resides in the Internal Operations component of Oracle Bills of Material, a module within Oracle E-Business Suite used to manage manufacturing bill-of-material structures. An authenticated attacker holding low-privileged credentials can send crafted HTTP requests to the affected interface. Exploitation is rated difficult due to preconditions outside the attacker's direct control, but a successful attack yields full compromise of Oracle Bills of Material. The scope change indicated in the CVSS vector means the impact extends beyond the vulnerable component to other products sharing the same execution context within the E-Business Suite stack. Oracle has not published root-cause specifics beyond the Critical Patch Update advisory.
Root Cause
Oracle's advisory does not disclose the underlying weakness class or CWE identifier. Based on the CVSS metrics, the defect permits an authenticated user of the Internal Operations component to influence application logic or data in a way that breaches the trust boundary between the vulnerable module and adjacent E-Business Suite components. See the Oracle Security Alert for authoritative technical guidance.
Attack Vector
The attack path requires network access to the E-Business Suite HTTP interface and a valid low-privileged account. The attacker crafts requests targeting the Internal Operations endpoints of Oracle Bills of Material. Because no user interaction is needed, the exploit can be automated once access preconditions are met. No public proof-of-concept code or exploit has been published, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.
No verified proof-of-concept code is available for this vulnerability. Refer to the Oracle Security Alert for vendor-provided technical details.
Detection Methods for CVE-2026-70718
Indicators of Compromise
- Unexpected HTTP requests to Oracle Bills of Material Internal Operations URLs originating from low-privileged E-Business Suite accounts.
- Anomalous privilege changes, new administrative sessions, or unauthorized data modifications within Bills of Material tables.
- Cross-module activity where a Bills of Material session accesses resources belonging to other E-Business Suite products, consistent with the scope change.
Detection Strategies
- Enable and review Oracle E-Business Suite application audit logs for unusual access patterns against Bills of Material Internal Operations forms and servlets.
- Correlate web-tier access logs with database-tier audit events to identify sessions performing operations outside a user's normal role.
- Baseline HTTP request patterns per user role and alert on deviations targeting Bills of Material endpoints.
Monitoring Recommendations
- Forward Oracle E-Business Suite application, web-tier, and database audit logs to a centralized SIEM for retention and correlation.
- Alert on repeated 4xx or 5xx responses from Bills of Material URLs, which may indicate exploitation attempts against difficult-to-reach code paths.
- Track authentication events for low-privileged accounts that suddenly interact with Internal Operations functionality.
How to Mitigate CVE-2026-70718
Immediate Actions Required
- Apply the fixes delivered in the Oracle August 2026 Critical Patch Update to all Oracle E-Business Suite instances running Bills of Material versions 12.2.3 through 12.2.15.
- Inventory all E-Business Suite environments, including non-production and disaster-recovery instances, and confirm patch coverage.
- Rotate credentials for any low-privileged accounts that had access to Bills of Material during the exposure window.
Patch Information
Oracle released the fix as part of the August 2026 Critical Patch Update. Consult the Oracle Security Alert for patch identifiers, prerequisites, and installation instructions specific to each supported 12.2.x version.
Workarounds
- Restrict network access to Oracle E-Business Suite HTTP endpoints using firewalls, reverse proxies, or Oracle E-Business Suite URL firewall configuration until patches are applied.
- Review and minimize privileges assigned to E-Business Suite accounts, removing unused responsibilities that grant access to Bills of Material Internal Operations.
- Enforce multi-factor authentication on E-Business Suite logins to raise the cost of credential-based access required to exploit the flaw.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

