Summary
CVE-2026-70795 is a high-severity vulnerability in the Oracle Applications Platform Engineering component (specifically the "Valid Session" sub-component) of Oracle E-Business Suite. The flaw allows a remote, unauthenticated attacker with network access via the Oracle Net protocol to compromise a target instance, with successful exploitation resulting in complete loss of confidentiality, integrity, and availability of the affected system.
Technical details
- Root cause: A weakness in the Valid Session handling within the Applications Platform Engineering component of Oracle E-Business Suite, which fails to properly enforce session validation under certain conditions.
- Attack vector: Network — exploitable remotely over the Oracle Net protocol without requiring proximity to the target.
- Privileges required: None — the vulnerability is exploitable by unauthenticated attackers.
- User interaction: None required.
- Attack complexity: High, per Oracle’s CVSS scoring, meaning successful exploitation depends on conditions outside the attacker’s control (e.g., specific configuration or timing).
- Impact: Successful exploitation can lead to complete compromise (confidentiality, integrity, and availability all rated High) of Oracle E-Business Suite.
Affected software
- Oracle E-Business Suite — Applications Platform Engineering component
- Affected versions: 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, and 12.2.15
Severity
- CVSS v3.1 Base Score: 8.1 (High)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the fix provided by Oracle for this vulnerability, published in Oracle’s August 2026 Critical Patch Update (Critical Security Patch Update), covering Oracle E-Business Suite versions 12.2.3 through 12.2.15. Organizations should upgrade to the patched release level indicated in Oracle’s official advisory for their specific 12.2.x branch.
- If immediate patching is not possible:
- Restrict network exposure of the Oracle Net listener and Oracle E-Business Suite application tier to trusted internal networks only; do not expose Oracle Net services directly to the internet.
- Apply network segmentation and firewall rules limiting access to Oracle E-Business Suite infrastructure to known, authorized hosts.
- Monitor Oracle E-Business Suite and Oracle Net traffic for anomalous or unauthenticated session activity as a compensating control until patching is complete.
- Given that this vulnerability requires no authentication and no user interaction, prioritize patching over compensating controls wherever feasible.

