Summary
CVE-2026-70773 is a vulnerability in the Knowledge Integration component of Oracle HCM Common Architecture, part of Oracle E-Business Suite. The flaw is remotely exploitable over HTTP by an unauthenticated attacker and, per Oracle’s own risk assessment, is "easily exploitable," allowing compromise of the component with unauthorized access to critical data and limited unauthorized data modification. Oracle rates the issue 8.2 (High) on the CVSS v3.1 scale.
Technical details
- Root cause: A flaw in the Knowledge Integration component of Oracle HCM Common Architecture that permits unauthorized access without requiring valid credentials.
- Trigger conditions: The vulnerability is reachable over the network via the HTTP protocol used by the affected component; no user interaction and no privileges are required to exploit it.
- Attack vector: Network (AV:N), low attack complexity (AC:L), no privileges required (PR:N), no user interaction (UI:N).
- Impact: High confidentiality impact (unauthorized read access to critical data) and low integrity impact (limited unauthorized modification of data); no impact to availability. Oracle notes that successful attacks can result in "unauthorized access to critical data or complete access to all Oracle HCM Common Architecture accessible data."
Affected software
- Oracle HCM Common Architecture (Oracle E-Business Suite), versions 12.2.3 through 12.2.15
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Patch Update / Security Alert fix for CVE-2026-70773 published in Oracle’s August 2026 Critical Patch Update, which addresses all supported Oracle E-Business Suite / Oracle HCM Common Architecture releases from 12.2.3 through 12.2.15. Organizations should upgrade to the patched release level identified in Oracle’s advisory as soon as possible.
- If immediate patching is not possible:
- Restrict network exposure of the Oracle HCM Common Architecture / E-Business Suite HTTP interfaces to trusted internal networks or VPN-only access, minimizing direct internet exposure.
- Deploy web application firewall (WAF) rules or reverse-proxy filtering in front of the affected endpoints to reduce unauthenticated exposure while patching is scheduled.
- Monitor logs for unusual unauthenticated requests to Knowledge Integration endpoints as an interim detection measure.
- Follow Oracle’s standard Critical Patch Update guidance, as Oracle states these fixes cannot be applied selectively and should be tested and deployed as a complete update.

