Description
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 4.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).
Published: 2026-07-21
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in the Oracle Workflow Notification Mailer component allows an unauthenticated attacker who can reach the system via the SMTP interface to write unauthorized data to or delete data from Oracle Workflow, or to trigger a partial denial of service. The flaw is a result of missing authentication controls (CWE-306) and the ability to send oversized or malformed requests (CWE-400).

Affected Systems

Oracle Corporation’s Oracle Workflow product, part of Oracle E-Business Suite, is affected for all released versions from 12.2.3 through 12.2.15.

Risk and Exploitability

The vulnerability has a CVSS 3.1 score of 4.8, indicating low to moderate impact on integrity and availability. EPSS is below 1%, reflecting a very low probability of exploitation. It is not listed in the CISA KEV catalog. The likely attack vector is network-based SMTP access, as the description notes that the vulnerability is exploitable with network access via SMTP.

Generated by OpenCVE AI on August 4, 2026 at 01:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑supplied patch or upgrade to a version later than 12.2.15
  • Configure firewall rules or secure SMTP gateways to allow only trusted hosts to communicate with the Workflow service
  • Enable comprehensive logging for Workflow actions and review logs for anomalous data changes or service restarts

Generated by OpenCVE AI on August 4, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated SMTP Exploit in Oracle Workflow Notification Mailer Leading to Data Modification and Partial Denial of Service

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated SMTP Exploit in Oracle Workflow Notification Mailer Leading to Data Modification and Partial Denial of Service

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unauthenticated SMTP Exploit in Oracle Workflow Notification Mailer

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated SMTP Exploit in Oracle Workflow Notification Mailer

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 4.8 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L).
First Time appeared Oracle
Oracle workflow
CPEs cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle workflow
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:17:11.228Z

Reserved: 2026-07-08T15:52:20.743Z

Link: CVE-2026-61247

cve-icon Vulnrichment

Updated: 2026-07-22T18:17:06.793Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function

  • CWE-400

    Uncontrolled Resource Consumption