Description
Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Oracle Compensation Workbench allows an attacker with low privileges and network access via HTTP to bypass proper access controls and obtain or alter sensitive compensation data. The weakness is an improper authorization flaw identified by CWE-284, which undermines the confidentiality and integrity of the application’s data. Exploitation can lead to both reading confidential records and performing unauthorized updates, inserts or deletes on the data stored within the system.

Affected Systems

The affected product is Oracle Compensation Workbench, part of Oracle E‑Business Suite. Versions 12.2.3 through 12.2.15 are impacted; any build within this series should be considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS 3.1 Base Score of 7.1 reflects a high severity level, while the EPSS score of less than 1% indicates that exploitation is currently uncommon. The vulnerability is not listed in the CISA KEV catalog. Attackers are expected to exploit the HTTP interface with low privileges, leveraging the improper access control to gain unauthorized data access or modify it. The risk remains significant for organizations that expose Compensation Workbench over the network without stringent authentication and authorization controls.

Generated by OpenCVE AI on August 4, 2026 at 02:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle CPU for July 2026, which provides the patch that fixes the improper access control defect in Compensation Workbench.
  • If the patch cannot be applied immediately, restrict HTTP traffic to the Compensation Workbench service to a whitelist of trusted IP addresses, thereby limiting the attack surface until a patch is available.
  • Enforce strict authentication and authorization on the application, ensuring only authorized roles can view or modify compensation data. Review and tighten custom roles and permissions that might expose data beyond intended users.

Generated by OpenCVE AI on August 4, 2026 at 02:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Improper Authorization in Oracle Compensation Workbench Enables Low‑Privilege Data Access
Weaknesses CWE-284

Thu, 30 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Network‑Based Attack Allows Unauthorized Access to Oracle Compensation Workbench Data
Weaknesses CWE-284

Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Network‑Based Attack Allows Unauthorized Access to Oracle Compensation Workbench Data
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Compensation Workbench product of Oracle E-Business Suite (component: Compensation Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Compensation Workbench. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Compensation Workbench accessible data as well as unauthorized update, insert or delete access to some of Oracle Compensation Workbench accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).
First Time appeared Oracle
Oracle compensation Workbench
CPEs cpe:2.3:a:oracle:compensation_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle compensation Workbench
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Oracle Compensation Workbench E-business Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:20:10.955Z

Reserved: 2026-07-08T15:51:55.591Z

Link: CVE-2026-60799

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:18.533

Modified: 2026-08-07T20:49:01.863

Link: CVE-2026-60799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:45:02Z

Weaknesses