Description
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: UWQ Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Universal Work Queue flaw allows an unauthenticated attacker with HTTP network access to influence critical data by creating, deleting, or modifying entries. Because the weakness relies on improper authentication and access control, it can lead to significant confidentiality and integrity loss for all data managed by the work queue. Successful exploitation does not grant full administrative rights, but it enables an attacker to corrupt or erase vital business processes and data sets.

Affected Systems

Oracle Universal Work Queue, part of the Oracle E‑Business Suite, is affected for supported releases 12.2.3 through 12.2.15. Any installation of these versions that exposes the UWQ server over the network is vulnerable.

Risk and Exploitability

With a CVSS 3.1 base score of 8.1, the vulnerability is classified as high severity. The EPSS score of less than 1% indicates low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Attacks would require an attacker to reach the UWQ server over HTTP and enlist a different human actor to trigger the malicious action, thereby limiting automated exploitation. Despite the low propagation risk, the potential for data compromise makes it a priority to contain the exposure.

Generated by OpenCVE AI on August 4, 2026 at 16:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Universal Work Queue to a patched release (at least 12.2.16) using the official CPU update process.
  • Restrict HTTP access to the UWQ server to trusted internal networks or VPN endpoints, blocking direct exposure to external connections.
  • Enforce strict application‑level authorization so that only authorized users may create, delete, or modify data within the work queue.

Generated by OpenCVE AI on August 4, 2026 at 16:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Authentication Bypass in Oracle Universal Work Queue
Weaknesses CWE-287

Thu, 30 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Web Access Allows Privilege Escalation in Oracle Universal Work Queue

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Web Access Allows Privilege Escalation in Oracle Universal Work Queue
Weaknesses CWE-284
CWE-287

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: UWQ Server Issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle universal Work Queue
CPEs cpe:2.3:a:oracle:universal_work_queue:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle universal Work Queue
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Universal Work Queue
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:24:44.374Z

Reserved: 2026-07-08T15:51:55.579Z

Link: CVE-2026-60700

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:48.730Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:10.483

Modified: 2026-07-30T17:35:32.450

Link: CVE-2026-60700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:13Z

Weaknesses