Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Oracle Work in Process, part of Oracle E‑Business Suite, enables an attacker with network access via HTTP to take full control of the application. The vulnerability lacks authentication checks and can be exploited to compromise confidentiality, integrity, and availability of the affected instance due to the CVSS 3.1 score of 9.8.

Affected Systems

The Oracle Work in Process product of Oracle E‑Business Suite – supported versions 12.2.3 through 12.2.15 – is affected. The issue resides in the Internal Operations component of the product.

Risk and Exploitability

Because the attack only requires network connectivity over HTTP and no valid credentials, the risk is high. The EPSS score of less than 1 percent suggests that active exploitation is currently rare, and the vulnerability is not yet listed in the CISA KEV catalog, but the severity remains critical. An unauthenticated attacker could execute arbitrary code or manipulate the application to achieve takeover of the entire Oracle Work in Process instance.

Generated by OpenCVE AI on August 5, 2026 at 01:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Work in Process patch or upgrade to a version newer than 12.2.15.
  • Restrict HTTP access to the Oracle Work in Process service so that only trusted internal networks can reach it.
  • Enforce strong authentication and proper access control checks within the application to prevent unauthorized use of its features.

Generated by OpenCVE AI on August 5, 2026 at 01:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Oracle Work in Process HTTP Remote Code Execution
Weaknesses CWE-284

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Oracle Work in Process HTTP Remote Code Execution
Weaknesses CWE-284

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title High‑Risk Remote Code Execution Vulnerability in Oracle Work in Process
Weaknesses CWE-20
CWE-284
CWE-79

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title High‑Risk Remote Code Execution Vulnerability in Oracle Work in Process
Weaknesses CWE-20
CWE-284
CWE-79

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:38:19.341Z

Reserved: 2026-07-08T15:51:55.598Z

Link: CVE-2026-60880

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:24.480

Modified: 2026-07-28T20:18:01.863

Link: CVE-2026-60880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:30:17Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function