6.8

CVE-2026-70715

Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer).  Supported versions that are affected are 26-26.1.0, 26.2.0, 26.3.1, 26.5.0 and  26.5.2. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Autonomous Health Framework executes to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Autonomous Health Framework Version >= 26.0.0 <= 26.1.0
Oracle ≫ Autonomous Health Framework Version 26.2.0
Oracle ≫ Autonomous Health Framework Version 26.3.1
Oracle ≫ Autonomous Health Framework Version 26.5.0
Oracle ≫ Autonomous Health Framework Version 26.5.2
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.197
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 0.9 5.9
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Oracle 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://www.oracle.com/security-alerts/cspuaug2026.html
Vendor Advisory