


Perceptive Security
SOC/SIEM Consultancy

Vulnerability in the Oracle Advanced Inbound Telephony product of Oracle E-Business Suite (component: Setup and Administration). Supported versions that are af…
Published:
20 April 2026 at 22:00:00
Alert date:
21 April 2026 at 22:04:46
Source:
nvd.nist.gov
Enterprise Applications
Critical vulnerability in Oracle Advanced Inbound Telephony component of Oracle E-Business Suite affecting versions 12.2.3-12.2.15. The vulnerability allows unauthenticated attackers with network access via HTTP to completely compromise the telephony system. The flaw is easily exploitable and requires no privileges or user interaction. Successful exploitation can result in complete takeover of Oracle Advanced Inbound Telephony with high impact to confidentiality, integrity, and availability. CVSS 3.1 Base Score is 9.8, indicating critical severity. The vulnerability is present in the Setup and Administration component.
Technical details
Mitigation steps:
Affected products:
Oracle E-Business Suite
Oracle Advanced Inbound Telephony
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-34275
https://www.oracle.com/security-alerts/cpuapr2026.html
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
