Description
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw exists in the Workflow Notification Mailer component of Oracle E‑Business Suite, allowing an unauthenticated attacker that can reach the system over HTTP to perform updates, inserts, or deletions of Oracle Workflow data, read restricted records, and trigger a partial denial of service. The weakness is a classic example of an improper access control flaw (CWE‑284) that compromises the confidentiality, integrity, and availability of the application.

Affected Systems

Affected systems are Oracle Workflow, specifically the Workflow Notification Mailer sub‑component of the Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are impacted; any deployment that exposes this component to the internet or an untrusted network is at risk.

Risk and Exploitability

The CVSS v3.1 base score of 7.3 indicates high severity, while the EPSS score of less than 1% shows a low but non‑zero likelihood of exploitation. Because the vulnerability requires only HTTP access and no prior authentication, exposed installations can be compromised quickly. Although the vulnerability is not listed in the CISA KEV catalog, the potential for unauthorized data manipulation and service disruption warrants prompt attention.

Generated by OpenCVE AI on August 2, 2026 at 23:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle E‑Business Suite patch that fixes CVE‑2026‑60143 to the Workflow Notification Mailer component
  • Restrict HTTP access to the Workflow Notification Mailer endpoint to trusted IP ranges or enforce VPN access to minimize exposure to untrusted networks
  • Disable or remove the Workflow Notification Mailer component from publicly accessible environments if it is not required, and block its HTTP port with firewall rules

Generated by OpenCVE AI on August 2, 2026 at 23:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated Web Access Enables Data Manipulation and Partial DoS in Oracle Workflow

Sat, 01 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification in Oracle Workflow Notification Mailer

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Access and Data Modification in Oracle Workflow Notification Mailer

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle workflow
CPEs cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle workflow
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T17:05:48.836Z

Reserved: 2026-07-08T15:51:40.514Z

Link: CVE-2026-60143

cve-icon Vulnrichment

Updated: 2026-07-23T16:54:21.211Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:00:04Z

Weaknesses