CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-70728

highCVSS 8.5covered by 2 sourcesfirst seen 2026-08-18
Oracle has resolved vulnerabilities in diverse Database products such as the Database Server, Essbase, Autonomous Health Framework and the Application Testing Suite. Oracle Database Server (versions 19.3 through 23.26.3) contains critical vulnerabilities in the RDBMS and Portable Clusterware components, including possibilities for unauthenticated attackers with physical or network access to gain control over clusterware, obtain complete control over the RDBMS, or perform unauthorized read and write operations. Some vulnerabilities require physical access to communication segments, others can be exploited via network access. Oracle Essbase has vulnerabilities that enable an attacker with network access via HTTP to achieve complete system compromise. Oracle Autonomous Health Framework contains multiple vulnerabilities in the Trace File Analyzer and Cluster Health Analyzer components, which enable unauthorized access, data manipulation and denial of service, depending on privileges and network access. Oracle Application Testing Suite version 13.3.0.1 contains diverse vulnerabilities that enable unauthenticated or low-privileged attackers with network access via HTTP(S) to create, modify or delete critical data, escalate privileges and achieve complete system compromise. These vulnerabilities can lead to data breaches, data manipulation, denial of service and complete system compromise.

CSIRTS triage

vendor: OracleRemote code executionAuthentication bypassInformation disclosurePrivilege escalationMisconfigurationaffected: Database Server 19.3 through 23.26.3; Essbase and Autonomous Health Framework versions unspecified
What
Multiple vulnerabilities in Oracle Database products enable unauthenticated attackers to gain control over clusterware, achieve complete RDBMS control, perform unauthorized read/write operations, and achieve complete system compromise.
Who is affected
Oracle Database Server versions 19.3–23.26.3, Oracle Essbase, Oracle Autonomous Health Framework, and Oracle Application Testing Suite users.
Urgency
Critical; vulnerabilities enable unauthenticated remote code execution and complete system compromise via network or physical access.
Action
Apply Oracle's critical security patches for all affected Database products; prioritize systems running Database versions 19.3–23.26.3.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-70728

Get an email if CVE-2026-70728 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-70728

CVE.org record

Embed the live status

CVE-2026-70728 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-70728 status](https://www.csirts.com/badge/CVE-2026-70728)](https://www.csirts.com/cve/CVE-2026-70728)