Description
Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-07-21
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Internal Operations component of Oracle Product Workbench allows an attacker with low privileges but network access over HTTP to bypass intended access controls. The vulnerability can be exploited to create, delete, or modify critical data or to gain full access to all data the product handles, thereby exposing the system to both confidentiality and integrity violations as reflected in the CVSS vector.

Affected Systems

Oracle Product Workbench versions 12.2.3 through 12.2.15 are affected. The flaw exists in the Internal Operations component of Oracle E‑Business Suite, and the only prerequisite for exploitation is a network connection to the application over HTTP.

Risk and Exploitability

The CVSS v3.1 base score of 8.1 indicates a high severity flaw. EPSS is reported as less than 1 %, suggesting that the likelihood of exploitation in the wild is very low at present. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires only standard HTTP connectivity and low privileges, so an attacker who can reach the target system can immediately exercise the erroneous access control and perform unauthorized data modifications.

Generated by OpenCVE AI on August 4, 2026 at 00:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Restrict external HTTP access to Oracle Product Workbench, allowing only trusted IPs or networks.
  • Re‑segment the network to isolate servers hosting Oracle Product Workbench from general user traffic, limiting the attack surface.
  • Apply any available Oracle patch that addresses the access‑control issue as soon as it is released.

Generated by OpenCVE AI on August 4, 2026 at 00:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low Privilege Access Control Exploit in Oracle Product Workbench

Sun, 02 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Oracle Product Workbench Access Control Exploit Allowing Unauthorized Data Modification

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Oracle Product Workbench Access Control Exploit Allowing Unauthorized Data Modification

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Product Workbench via Access Control Flaw

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification in Oracle Product Workbench via Access Control Flaw

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle product Workbench
CPEs cpe:2.3:a:oracle:product_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle product Workbench
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Product Workbench
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:46:26.671Z

Reserved: 2026-07-08T15:52:20.748Z

Link: CVE-2026-61335

cve-icon Vulnrichment

Updated: 2026-07-22T17:46:13.892Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses