Description
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability enables a high‑privileged attacker with network access to the HTTP interface of Oracle Universal Work Queue to compromise the Work Provider Site Level Administration component. The impact is severe, as it can lead to full control over the application, exposing all confidential data stored in the work queue as well as the underlying database. The weakness is essentially an authorization flaw, allowing privilege escalation that affects all three security objectives: confidentiality, integrity, and availability.

Affected Systems

Oracle Universal Work Queue in Oracle E‑Business Suite versions 12.2.3 through 12.2.15 are affected. Any deployment that exposes the Work Provider Site Level Administration over HTTP without proper access controls falls within the scope of this vulnerability.

Risk and Exploitability

The CVSS 3.1 base score of 6.6 indicates moderate severity; the vector AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H shows that a network attacker must already possess high privileges, likely administrative credentials, before exploitation. The EPSS score of less than 1% signals very low probability of real‑world exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The described attack path involves leveraging exposed HTTP services to bypass authorization checks, which implies that when high‑privilege credentials are available, the attacker can take over the whole system. Organizations should treat this as a high‑priority risk if the affected versions are in use.

Generated by OpenCVE AI on August 2, 2026 at 21:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Oracle's security patch released in the July 2026 CPU to Oracle Universal Work Queue
  • Restrict physical and network access to the Work Provider Site Level Administration by placing it behind a VPN or firewall rule that only allows trusted hosts
  • Disable any unused HTTP endpoints or administrative features that are not required for business operations

Generated by OpenCVE AI on August 2, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title High-Privilege Exploitation of Oracle Universal Work Queue Administration

Tue, 28 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Oracle Universal Work Queue: High‑Privilege HTTP‑Exposed Authorization Flaw
Weaknesses CWE-285
CWE-732

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Oracle Universal Work Queue: High‑Privilege HTTP‑Exposed Authorization Flaw
Weaknesses CWE-285
CWE-732

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle universal Work Queue
CPEs cpe:2.3:a:oracle:universal_work_queue:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle universal Work Queue
References
Metrics cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Universal Work Queue
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:24:37.195Z

Reserved: 2026-07-08T15:51:55.579Z

Link: CVE-2026-60701

cve-icon Vulnrichment

Updated: 2026-07-24T15:04:46.758Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:10.597

Modified: 2026-07-30T17:35:39.937

Link: CVE-2026-60701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses