cve-2026-70941
HIGH CVSS 8.8 opencveVulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
- Published
- 2026-08-18 21:17 UTC
- Last Modified
- 2026-08-28
CVSS details not available.
No product information available.
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 3.1 | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
mitre | ||
| 3.1 | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
nvd | ||
| 3.1 | 8.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
opencve |
No references available.
No linked vulnerabilities found.
{
"cve": "CVE-2026-70941",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "[12.2.3,12.2.15]"
}
}
],
"enrichment": {
"confidence": 95.0,
"confidence_source": "inferred",
"scores": [
{
"score": 95.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "Oracle Payroll",
"source": "cna",
"vendor": "Oracle Corporation"
},
"product": "payroll",
"vendor": "oracle"
}
],
"created": "2026-08-19T04:00:11.424430+00:00",
"title": "Local Privilege Escalation Enables Full Compromise of Oracle Payroll",
"updated": "2026-08-22T08:00:13.613889+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$payroll"
]
},
"epss": {
"score": 0.00161
},
"mitre": {
"cpes": [
"cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:02:37.810000+00:00",
"description": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"mitre_repo_path": "cves/2026/70xxx/CVE-2026-70941.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-22T03:15:20.617000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$payroll"
],
"weaknesses": []
},
"nvd": {
"cpes": [
"cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*"
],
"created": "2026-08-18T21:17:52.227000+00:00",
"description": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
"cvssV4_0": {}
},
"nvd_repo_path": "2026/CVE-2026-70941.json",
"references": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"title": null,
"updated": "2026-08-28T14:43:59.967000+00:00",
"vendors": [
"oracle",
"oracle$PRODUCT$payroll"
],
"weaknesses": [
"CWE-284"
]
},
"opencve": {
"changes": [
{
"created": "2026-08-18T21:15:00+00:00",
"data": [
{
"details": {
"new": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"old": null
},
"type": "description"
},
{
"details": [
"oracle",
"oracle$PRODUCT$payroll"
],
"type": "first_time"
},
{
"details": {
"added": [
"cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"oracle",
"oracle$PRODUCT$payroll"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 8.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "429e0ae4-45ad-4434-b4d5-f645f8f93380"
},
{
"created": "2026-08-19T04:15:00+00:00",
"data": [
{
"details": {
"new": "Low Privileged Local Attack Allows Oracle Payroll Compromise with Scope Expansion",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-284"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "51c5fee1-e681-4f71-b414-654d47203c18"
},
{
"created": "2026-08-20T09:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Low Privileged Local Attack Allows Oracle Payroll Compromise with Scope Expansion"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-284"
]
},
"type": "weaknesses"
}
],
"id": "c9d7e6df-5b50-4525-ac18-da1ddd4dd8b8"
},
{
"created": "2026-08-21T03:45:00+00:00",
"data": [
{
"details": {
"new": "Local Privilege Escalation in Oracle Payroll Leading to System Compromise",
"old": null
},
"type": "title"
},
{
"details": {
"added": [
"CWE-269"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "6f9db4e5-a108-4c46-889e-81639accc487"
},
{
"created": "2026-08-22T04:30:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-284"
],
"removed": []
},
"type": "weaknesses"
}
],
"id": "f3b651d5-ab62-4a83-86e6-d3db75506b81"
},
{
"created": "2026-08-22T06:30:00+00:00",
"data": [
{
"details": {
"new": null,
"old": "Local Privilege Escalation in Oracle Payroll Leading to System Compromise"
},
"type": "title"
},
{
"details": {
"added": [],
"removed": [
"CWE-269"
]
},
"type": "weaknesses"
}
],
"id": "dca19c8e-3153-47f6-8dc7-0322633572be"
},
{
"created": "2026-08-22T08:15:00+00:00",
"data": [
{
"details": {
"new": "Local Privilege Escalation Enables Full Compromise of Oracle Payroll",
"old": null
},
"type": "title"
}
],
"id": "79716f4b-fad6-45b4-afb6-a61ba38fbaab"
}
],
"cpes": {
"data": [
"cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-08-18T21:02:37.810000+00:00",
"provider": "mitre"
},
"description": {
"data": "Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 8.8,
"vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {},
"provider": null
},
"epss": {
"data": {
"score": 0.00161
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {},
"provider": null
},
"threat_severity": {
"data": null,
"provider": null
}
},
"references": {
"data": [
"https://www.oracle.com/security-alerts/cspuaug2026.html"
],
"providers": [
"mitre",
"nvd"
]
},
"title": {
"data": "Local Privilege Escalation Enables Full Compromise of Oracle Payroll",
"provider": "enrichment"
},
"updated": {
"data": "2026-08-22T08:00:13.613889+00:00",
"provider": "enrichment"
},
"vendors": {
"data": [
"oracle",
"oracle$PRODUCT$payroll"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-284"
],
"providers": [
"nvd"
]
}
}
}