Description
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Oracle Workflow Notification Mailer allows an attacker who can reach the service over HTTP to perform unauthorized create, read, update and delete operations on Workflow data and to cause a partial service outage. The vulnerability gives the attacker both read and write capabilities on a subset of Workflow data while also exposing the system to a potential denial of service.

Affected Systems

Oracle Corporation’s Oracle Workflow product in Oracle E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 of the Workflow component are vulnerable. Applications running these versions should be reviewed to confirm they host the affected component.

Risk and Exploitability

The CVSS v3.1 base score of 6.3 indicates moderate severity with low or moderate impacts on confidentiality, integrity and availability. The EPSS score indicates an exploitation probability of less than 1 %. The vulnerability is not listed in the CISA KEV catalog, which suggests no known, actively exploited instances. The attack vector is limited to network traffic over HTTP, which requires the attacker to have network access to the Workflow service. Given these factors, the risk remains moderate, but the presence of a low‑privilege attacker on the network justifies prompt remediation.

Generated by OpenCVE AI on August 4, 2026 at 01:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Oracle Workflow to a version that contains the fix; Oracle publishes security patch updates in their CPU releases
  • Restrict HTTP access to the Workflow service via firewall rules or network segmentation so only trusted hosts can reach it
  • Enforce least privilege by limiting Workflow user accounts to the minimum permissions required for their functions

Generated by OpenCVE AI on August 4, 2026 at 01:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Partial Denial of Service via Workflow Notification Mailer

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access and Partial Denial of Service via Workflow Notification Mailer

Tue, 28 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Low Privilege Access Control Failure in Oracle Workflow Notification Mailer

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low Privilege Access Control Failure in Oracle Workflow Notification Mailer

Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Workflow accessible data as well as unauthorized read access to a subset of Oracle Workflow accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Workflow. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle workflow
CPEs cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle workflow
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T14:51:26.537Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61278

cve-icon Vulnrichment

Updated: 2026-07-22T14:50:38.625Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses