Summary
CVE-2026-70704 is a high-severity (CVSS 8.1) vulnerability in the Party Search UI component of Oracle Trading Community, a module within Oracle E-Business Suite. The flaw allows an unauthenticated attacker with network access via HTTP to compromise Oracle Trading Community, with Oracle’s advisory noting that successful exploitation "can result in takeover" of the affected component. Oracle rates this as difficult to exploit (high attack complexity) but requiring no credentials and no user interaction.
Technical details
- Root cause: A vulnerability in the Party Search UI component of Oracle Trading Community that permits unauthorized access/manipulation without authentication.
- Trigger conditions: Exploitation requires the attacker to have network access to the exposed EBS/Trading Community HTTP interface; Oracle rates attack complexity as High, meaning exploitation depends on conditions outside the attacker’s direct control or requires specialized preparation.
- Attack vector: Network (HTTP), unauthenticated, no user interaction required.
- Impact: High impact to confidentiality, integrity, and availability; Oracle states successful attacks can result in complete takeover of Oracle Trading Community.
Affected software
- Oracle E-Business Suite — Oracle Trading Community, versions 12.2.3 through 12.2.15
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided in Oracle’s August 2026 Critical Security Patch Update (CSPU), released August 18, 2026, which addresses CVE-2026-70704 for Oracle Trading Community versions 12.2.3–12.2.15.
- If patching cannot be applied immediately: Restrict network exposure of Oracle E-Business Suite / Trading Community HTTP interfaces (e.g., limit access to trusted internal networks or VPN, avoid direct internet exposure), and monitor logs for anomalous or unauthenticated requests to Party Search UI endpoints until the patch can be applied. Oracle strongly recommends applying CSPU fixes as soon as possible.

