Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. While the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Fri, 21 Aug 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Data Access via Improper Access Control in Oracle MES | |
| Weaknesses | CWE-284 |
Fri, 21 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privileged Access to Critical Data in Oracle MES for Process Manufacturing | |
| Weaknesses | CWE-284 |
Wed, 19 Aug 2026 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Low Privileged Access to Critical Data in Oracle MES for Process Manufacturing | |
| Weaknesses | CWE-284 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. While the vulnerability is in Oracle MES for Process Manufacturing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle MES for Process Manufacturing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N). | |
| First Time appeared |
Oracle
Oracle mes For Process Manufacturing |
|
| CPEs | cpe:2.3:a:oracle:mes_for_process_manufacturing:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle mes For Process Manufacturing |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-08-18T21:02:02.002Z
Reserved: 2026-08-04T22:06:34.599Z
Link: CVE-2026-70827
No data.
Status : Awaiting Analysis
Published: 2026-08-18T21:17:37.833
Modified: 2026-08-20T13:07:28.683
Link: CVE-2026-70827
No data.
OpenCVE Enrichment
Updated: 2026-08-21T06:45:03Z
Weaknesses