Description
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Non-Media Integration issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Universal Work Queue is affected by a low‑privileged network vulnerability that permits an attacker with HTTP access to create, delete, or modify critical data. This flaw is a weakness in access control (CWE‑284) that exposes confidentiality and integrity of all accessible data without impacting availability. Successful exploitation allows unauthorized users to change or delete information that is integral to the organization’s operations.

Affected Systems

Oracle Corporation’s Oracle Universal Work Queue product, versions 12.2.3 through 12.2.15, is vulnerable. The issue is rooted in non‑media integration components and applies to any instance reachable over HTTP.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 reflects a high confidentiality and integrity impact with a network attack vector, low attack complexity, and low privilege requirement. The EPSS indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA KEV, and the attack likely proceeds via direct HTTP requests to the affected service, allowing low‑privileged users to execute unauthorized operations.

Generated by OpenCVE AI on August 4, 2026 at 02:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Universal Work Queue security patch or update for versions 12.2.3 to 12.2.15 as announced in the Oracle security advisory
  • Restrict HTTP traffic to the Universal Work Queue to trusted IP ranges or a VPN to limit exposure
  • Review and enforce strict access control policies ensuring that only authorized users can perform create, delete, or modify actions on the service

Generated by OpenCVE AI on August 4, 2026 at 02:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Enables Unauthorized Modification or Deletion of Critical Data in Oracle Universal Work Queue

Sun, 02 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Access Enables Unauthorized Modification or Deletion of Critical Data in Oracle Universal Work Queue

Thu, 30 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Low‑Privilege HTTP Access in Oracle Universal Work Queue

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Manipulation via Low‑Privilege HTTP Access in Oracle Universal Work Queue
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Non-Media Integration issues). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Universal Work Queue accessible data as well as unauthorized access to critical data or complete access to all Oracle Universal Work Queue accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle universal Work Queue
CPEs cpe:2.3:a:oracle:universal_work_queue:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle universal Work Queue
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Universal Work Queue
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T15:08:27.134Z

Reserved: 2026-07-08T15:51:55.606Z

Link: CVE-2026-60997

cve-icon Vulnrichment

Updated: 2026-07-24T15:08:12.817Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses