Description
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Workbench accessible data as well as unauthorized read access to a subset of Oracle Product Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Workbench. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Product Workbench’s WebUI permits any low‑privileged HTTP attacker to bypass authorization controls and gain unauthorized create, read, update, and delete access to a subset of data, as well as cause a partial denial of service. The weakness is an access control flaw (CWE‑284) that allows unauthorized manipulation of data and disruption of service without user interaction.

Affected Systems

The affected product is Oracle Product Workbench from Oracle Corporation, versions 12.2.3 through 12.2.15. These releases are web interface exposed over HTTP.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, with low confidentiality, integrity, and availability impacts. The EPSS value of less than 1% suggests a small likelihood of exploitation in the wild, and it is not listed in the CISA KEV catalog. Attackers can exploit the flaw to the WebUI, using only low privileges, so the risk remains significant for exposed instances.

Generated by OpenCVE AI on August 4, 2026 at 01:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Oracle Product Workbench to a version that is not affected by the vulnerability, applying the patch from the Office of the Product Security Alerts for July 2026.
  • Restrict public network access to the WebUI component by firewall rules or placing it behind a strict authentication gateway to limit low reach.
  • Enforce least‑privilege policies and monitor database operations for anomalous insert, update, or delete activity to detect and block abuse of the WebUI.

Generated by OpenCVE AI on August 4, 2026 at 01:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Access Control Weakness in Oracle Product Workbench WebUI Enables Unauthorized CRUD and Partial Denial of Service

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Partial Denial of Service via HTTP in Oracle Product Workbench WebUI

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Partial Denial of Service via HTTP in Oracle Product Workbench WebUI

Mon, 27 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged WebUI Authorization Bypass in Oracle Product Workbench

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low‑Privileged WebUI Authorization Bypass in Oracle Product Workbench

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Product Workbench accessible data as well as unauthorized read access to a subset of Oracle Product Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Product Workbench. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle product Workbench
CPEs cpe:2.3:a:oracle:product_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Workbench
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Product Workbench
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T15:12:59.263Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61269

cve-icon Vulnrichment

Updated: 2026-07-22T15:12:40.856Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses