Summary
CVE-2026-70852 is a high-severity vulnerability in the Oracle Demand Planning module of Oracle E-Business Suite (component: Internal Operations). The flaw allows a remote, unauthenticated attacker with network access via HTTP to obtain complete read access to all data accessible to Oracle Demand Planning, along with the ability to insert, update, or delete a subset of that data. Oracle disclosed the issue as part of its August 2026 Critical Security Patch Update.
Technical details
- Root cause: A flaw in the Oracle Demand Planning component of Oracle E-Business Suite that fails to properly enforce access controls on data operations, as described in Oracle’s advisory.
- Trigger conditions: The vulnerability is remotely exploitable over HTTP and does not require any authentication or user interaction to trigger.
- Attack vector: Network (AV:N) — exploitable by an attacker with mere network access to the affected HTTP-based Oracle Demand Planning interface; low attack complexity (AC:L) and no privileges required (PR:N).
- Impact: Successful exploitation grants complete access (confidentiality: High) to all data accessible through Oracle Demand Planning, plus limited unauthorized insert, update, or delete capability (integrity: Low) on some of that data. There is no impact to availability per Oracle’s scoring.
Affected software
- Oracle E-Business Suite — Oracle Demand Planning component
- Version 12.1
- Version 12.2
Severity
- CVSS v3.1 Base Score: 8.2 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Mitigation and recommended actions
- Immediate: Apply the Oracle Critical Security Patch Update released in August 2026, which contains the fix for CVE-2026-70852. Oracle strongly recommends applying security patches as soon as possible.
- If immediate patching is not possible:
- Restrict network-level access to Oracle E-Business Suite Demand Planning interfaces to trusted internal networks only, minimizing direct exposure to the internet.
- Monitor Oracle E-Business Suite HTTP access logs for anomalous, unauthenticated requests targeting the Demand Planning module.
- Review data access and audit logs for the Demand Planning component for signs of unauthorized data retrieval or modification predating patch deployment.
- Follow Oracle’s documented security hardening guidance for E-Business Suite deployments while patch validation and rollout are completed.

