Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Work in Process accessible data as well as unauthorized update, insert or delete access to some of Oracle Work in Process accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in Oracle Work in Process’s Internal Operations component of Oracle E‑Business Suite. An attacker with low‑privileged access and HTTP network connectivity can exploit it to read all data that the process can see, and in some scenarios can also insert, update or delete data. The vulnerability requires that a user other than the attacker interact with the system, and it can affect additional Oracle products through a scope change. This leads to confidentiality and limited integrity compromises.

Affected Systems

Oracle Work in Process (Oracle E‑Business Suite component) versions 12.2.3 to 12.2.15 are affected.

Risk and Exploitability

The CVSS base score of 7.6 indicates high severity, while the EPSS score of less than 1% suggests a very low but non‑zero chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation is possible over HTTP with a low‑privilege attacker, but it calls for human interaction from a different user. If leveraged, the attacker could gain unauthorized read, and in some cases write access to critical data, which would jeopardize both confidentiality and integrity. Administrators should view this as a medium‑to‑high risk with low probability of exploitation.

Generated by OpenCVE AI on August 4, 2026 at 16:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Work in Process patch released in the July 2026 security update, upgrading to version 12.2.16 or later.
  • Restrict HTTP access to the Oracle Work in Process backend to trusted personnel and isolated networks, using firewalls or VPN controls.
  • Strengthen internal access controls, ensuring that only authorized roles have read/write privileges to Oracle Work in Process data, following the principle of least privilege.

Generated by OpenCVE AI on August 4, 2026 at 16:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Authorization Bypass in Oracle Work in Process
Weaknesses CWE-272
CWE-285

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Work in Process Allows Unauthorized Data Access and Modification
Weaknesses CWE-284

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Improper Access Control in Oracle Work in Process Allows Unauthorized Data Access and Modification
Weaknesses CWE-284

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Oracle Work in Process Vulnerability Enables Unauthorized Data Access with Low Privilege
Weaknesses CWE-200
CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle Work in Process Vulnerability Enables Unauthorized Data Access with Low Privilege
Weaknesses CWE-200
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Work in Process, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Work in Process accessible data as well as unauthorized update, insert or delete access to some of Oracle Work in Process accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N'}


Subscriptions

Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:37:30.028Z

Reserved: 2026-07-08T15:51:55.598Z

Link: CVE-2026-60886

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:24.593

Modified: 2026-07-28T19:46:34.330

Link: CVE-2026-60886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:45:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-269

    Improper Privilege Management

  • CWE-272

    Least Privilege Violation

  • CWE-285

    Improper Authorization

  • CWE-352

    Cross-Site Request Forgery (CSRF)