Description
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Workflow product contains a flaw in its Notification Mailer component that allows an attacker with low privileges and network access via HTTP to modify, insert, or delete data that is normally protected, read restricted data, and create a partial denial of service. This weakness aligns with improper access control and missing authorization, enabling compromise of confidentiality, integrity, and availability.

Affected Systems

Oracle Corporation’s Oracle Workflow component of Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15, are affected by this vulnerability.

Risk and Exploitability

The CVSS 3.1 base score of 6.3 indicates moderate severity while the EPSS score of less than 1% suggests a very low probability of exploitation at this time. It is not listed in CISA’s KEV catalog. The likely attack vector is via network HTTP access, as the description states that low privileged attackers with such access can exploit the flaw. Successful exploitation would permit unauthorized data modification, read access, and a limited denial of service for the Oracle Workflow service.

Generated by OpenCVE AI on August 4, 2026 at 03:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle’s official security patch for CVE-2026-60575 to all affected instances; the patch addresses the improper access control (CWE‑284) that allows unauthorized data manipulation in the Notification Mailer component.
  • Until the patch is available, block unauthenticated HTTP requests targeting the Workflow Notification Mailer using firewall rules or ACLs to enforce proper authorization controls (CWE‑862), thereby preventing low‑privilege attackers from exploiting access that should be limited.
  • If disabling or removing the Workflow Notification Mailer is feasible, do so to eliminate the exposed authorization path. If the component is required, restrict its administrative interface to privileged accounts and isolate it from the public network.

Generated by OpenCVE AI on August 4, 2026 at 03:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Oracle Workflow Notification Mailer

Sat, 01 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Access via Oracle Workflow Notification Mailer

Thu, 30 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Partial Denial of Service via Workflow Notification Mailer
Weaknesses CWE-862

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation and Partial Denial of Service via Workflow Notification Mailer
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle workflow
CPEs cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle workflow
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-27T15:21:15.980Z

Reserved: 2026-07-08T15:51:40.545Z

Link: CVE-2026-60575

cve-icon Vulnrichment

Updated: 2026-07-27T15:21:08.314Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T03:45:03Z

Weaknesses