Description
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. While the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-06-16
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vulnerability in the Oracle Universal Work Queue product, specifically the Work Provider Site Level Administration component, permits a low‑privileged attacker with network access via HTTP to compromise the system. Successful exploitation results in a full takeover of the Oracle Universal Work Queue, impacting confidentiality, integrity, and availability. The CVSS 3.1 rating is 9.9 with a vector indicating network access, low attack complexity, low privileges, no user interaction, and a scope change that may affect additional components. This indicates a severe remote code execution scenario.

Affected Systems

Oracle Universal Work Queue of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are affected; no other versions are listed as impacted. The flaw resides in the Work Provider Site Level Administration sub‑component.

Risk and Exploitability

The CVSS base score of 9.9 marks it as critical. Though the EPSS indicates a very low exploitation probability (<1%), the existence of a remote HTTP interface and the scope‑changing nature of the bug means that attackers can act from outside the organization with simple credentials. The vulnerability is not listed in CISA’s KEV catalog. Any exploitation requires network connectivity to the affected HTTP service and a low‑privileged account, after which the attacker can gain full control of the Oracle Universal Work Queue and potentially additional components.

Generated by OpenCVE AI on June 17, 2026 at 18:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch or upgrade Oracle Universal Work Queue to a version earlier than 12.2.3 or later than 12.2.15 that contains the fix.
  • Restrict HTTP access to the Universal Work Queue to trusted administrative hosts or IP ranges, and block low‑privileged external users from reaching the Work Provider Site Level Administration interface.
  • Monitor authentication and access logs for abnormal reconnaissance or elevation attempts and configure alerts for suspicious activity.

Generated by OpenCVE AI on June 17, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 16 Jun 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. While the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle universal Work Queue
CPEs cpe:2.3:a:oracle:universal_work_queue:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle universal Work Queue
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Universal Work Queue
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-06-17T17:40:54.120Z

Reserved: 2026-05-18T15:55:10.314Z

Link: CVE-2026-46964

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T03:00:16Z

Weaknesses

No weakness.