← All Advisories

Oracle Financial Services Infrastructure Platform Access Control Flaw Scores 7.5

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2026-22010

Key Details

CVECVE-2026-22010
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is none; availability impact is none.
Affected productsOracle Financial Services Analytical Applications Infrastructure
Classified asCWE-284 (Improper Access Control)
Exploitation prediction (EPSS)0.31% probability of exploitation in the next 30 days (21% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
OracleFinancial Services Analytical Applications Infrastructure
SubsystemsGeneral OT
SectorsMultiple

What to Know

Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Platform). Supported versions that are affected are 8.0.7.9, 8.0.8.7 and 8.1.2.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

What to Do

Monitor Oracle's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-22010
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-22010
Vendor advisoryhttps://www.oracle.com/security-alerts/cpuapr2026.html