THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70846 (CRITICAL 9.6) — Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle

[NVD] CVE-2026-70846 (CRITICAL 9.6) — Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle

mednvdPublished 2026-08-18

CVE-2026-70846 CVSS: 9.6 CRITICAL Published: 2026-08-18T21:17:40.430

Vulnerability in the Oracle Demand Planning product of Oracle Supply Chain (component: Internal Operations). Supported versions that are affected are 12.1 and 12.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Planning. While the vulnerability is in O

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70846