Description
Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Business Process Management Suite. While the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Process Management Suite. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Human Workflow component of Oracle Business Process Management Suite contains a flaw that can be triggered by an attacker with network access to the T3 or IIOP protocols. The vulnerability enables the attacker to execute code within the context of the application, leading to full compromise of the Business Process Management Suite. The flaw is rated CVSS 3.1 score 9.9, indicating severe confidentiality, integrity, and availability impact.

Affected Systems

Oracle Business Process Management Suite versions 12.2.1.4.0 and 14.1.2.0.0 are affected. This part of Oracle Fusion Middleware can be reached over T3 or IIOP. The functionality is exposed to any user with low privileges on the network.

Risk and Exploitability

The CVSS base score of 9.9 combined with an EPSS score of less than 1% shows a highly critical flaw that is unlikely to be widely exploited yet remains a significant risk. The vulnerability is listed as "not in KEV" but the scope change suggests potential impact on additional Oracle products. Successful exploitation requires only network connectivity to the vulnerable ports; no special credentials are needed. An attacker from an untrusted network can therefore compromise the system by sending the crafted payload over T3 or IIOP.

Generated by OpenCVE AI on August 4, 2026 at 03:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle patch for Oracle Business Process Management Suite from the July 2026 CPU update.
  • Restrict inbound traffic on T3 and IIOP ports to trusted networks through firewall rules or network segmentation.
  • Enforce strict access controls and least‑privilege policies on Human Workflow operations to address improper access control (CWE-284).
  • Enable detailed auditing of Human Workflow actions and monitor for anomalous behavior that may indicate exploitation.

Generated by OpenCVE AI on August 4, 2026 at 03:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Remote Exploit of Oracle Business Process Management Suite Human Workflow

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Business Process Management Suite Human Workflow Remote Code Execution
Weaknesses CWE-94

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Business Process Management Suite Human Workflow Remote Code Execution
Weaknesses CWE-94

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Human Workflow). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Business Process Management Suite. While the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Process Management Suite. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle business Process Management Suite
CPEs cpe:2.3:a:oracle:business_process_management_suite:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:business_process_management_suite:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle business Process Management Suite
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Business Process Management Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T11:07:59.482Z

Reserved: 2026-07-08T15:51:40.543Z

Link: CVE-2026-60542

cve-icon Vulnrichment

Updated: 2026-07-27T11:07:55.638Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses