CVE-2026-70689 – Oracle Essbase
CVSS 9.8
CRITICAL
Critical - Same Day Deployment
“An unauthenticated HTTP request can lead to full takeover of the affected Essbase environment.”
Oracle addresses a Critical vulnerability in the Infrastructure component of Oracle Essbase. CVE-2026-70689 allows an unauthenticated attacker with network access over HTTP to compromise Oracle Essbase, with successful exploitation resulting in takeover of the application. The CVSS score is 9.8, which is Critical severity.
Oracle Essbase 21.8.1.0.0 is affected. The issue is addressed in Oracle’s August 2026 Critical Security Patch Update.
Key Details
- Affected Product
- Oracle Essbase
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-284
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.