Summary
CVE-2026-70722 is a high-severity vulnerability affecting the Oracle Advanced Inbound Telephony product within Oracle E-Business Suite (component: Internal Operations). The flaw allows an unauthenticated, remote attacker with network access via HTTPS to compromise the affected component, resulting in unauthorized creation, deletion, or modification of critical data and a partial denial of service. Oracle rates this vulnerability as easily exploitable, and it carries a CVSS v3.1 base score of 8.2 (High).
Technical details
- Root cause: A flaw in the Internal Operations component of Oracle Advanced Inbound Telephony that permits an attacker to alter or destroy application data without authentication.
- Trigger conditions: The vulnerable component must be network-reachable over HTTPS; no valid credentials, privileges, or user interaction are required to exploit it.
- Attack vector: Network (remote), low attack complexity, no privileges required (PR:N), no user interaction (UI:N), scope unchanged.
- Impact: High integrity impact — attackers can create, delete, or modify critical data, potentially affecting all data accessible to Oracle Advanced Inbound Telephony. Additionally, there is a low availability impact, enabling a partial denial of service against the component. Confidentiality is not impacted (C:N).
Affected software
- Oracle E-Business Suite — Oracle Advanced Inbound Telephony, versions 12.2.3 through 12.2.15 (inclusive).
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update (CPU) for August 2026, which addresses CVE-2026-70722 for Oracle Advanced Inbound Telephony versions 12.2.3–12.2.15. Update to the version specified by Oracle in the corresponding CPU risk matrix as soon as possible.
- If immediate patching is not feasible: Restrict and monitor network/HTTPS access to Oracle E-Business Suite Advanced Inbound Telephony components (e.g., via firewall rules, VPN-only access, or web application firewall policies) to limit exposure to trusted networks until the patch can be applied. Review Oracle E-Business Suite instances for internet exposure and prioritize patching for any externally reachable systems.
- Continue to follow Oracle’s standard E-Business Suite hardening guidance and monitor Oracle’s security alert channels for any updates on exploitation activity related to this CVE.

