Description
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Workflow executes to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Workflow as well as unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized read access to a subset of Oracle Workflow accessible data. CVSS 3.1 Base Score 5.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H).
Published: 2026-07-21
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Workflow’s Notification Mailer component allows an attacker with high privileged local access to the system where Oracle Workflow runs to trigger a hang or crash, effectively causing a denial of service. The same privilege can also be used to update, insert, delete, or read data that belongs to the component, resulting in unauthorized data access. These impacts are reflected in the CVSS 3.1 base score of 5.2, which indicates low confidentiality and integrity damage but high availability loss.

Affected Systems

The vulnerability affects the Oracle Workflow product that is part of Oracle E‑Business Suite. All supported releases from version 12.2.3 through 12.2.15 contain the vulnerable component and are therefore subject to this issue.

Risk and Exploitability

The CVSS score indicates moderate severity, and the EPSS score is below 1%. The exploit requires the attacker to already have local high‑privileged access and is described as difficult to exploit. Consequently, the likelihood of widespread attacks is low, but the risk remains for systems where privileged users or compromised local accounts have access to Oracle Workflow.

Generated by OpenCVE AI on August 2, 2026 at 23:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Consult the Oracle CPU alert at https://www.oracle.com/security-alerts/cpujul2026.html to determine whether an official fix or upgrade is available and apply it when released.
  • If no patch is available, upgrade to a non‑affected release of Oracle E‑Business Suite or remove the vulnerable component from the environment.
  • Until a fix can be applied, limit the privilege of local accounts that can access the workflow infrastructure and enforce least‑privilege principles.
  • Continuously monitor system logs for abnormal hangs, crashes, or unauthorized data modification attempts, and respond promptly to any anomalies.

Generated by OpenCVE AI on August 2, 2026 at 23:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Oracle Workflow Notification Mailer Vulnerability Enables Denial of Service and Unauthorized Data Access

Sun, 26 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Oracle Workflow Notification Mailer Vulnerability Enables Denial of Service and Unauthorized Data Access

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Workflow executes to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Workflow as well as unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized read access to a subset of Oracle Workflow accessible data. CVSS 3.1 Base Score 5.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H).
First Time appeared Oracle
Oracle workflow
CPEs cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle workflow
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:20:32.963Z

Reserved: 2026-07-08T15:51:40.514Z

Link: CVE-2026-60149

cve-icon Vulnrichment

Updated: 2026-07-23T15:20:27.757Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T00:00:04Z

Weaknesses