Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-08-18
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in Oracle Work in Process, part of the Oracle E‑Business Suite, where an attacker who can log into the same infrastructure may use local privileges to compromise the application. The effect is a full takeover of Oracle Work in Process, resulting in complete loss of confidentiality, integrity, and availability for that component. The weakness is an improper access control flaw.

Affected Systems

Oracle Corporation’s Work in Process component of Oracle E‑Business Suite is affected. Versions 12.2.3 through 12.2.15 are vulnerable. The vulnerability is present in the internal operations part of the product.

Risk and Exploitability

The CVSS v3.1 base score of 7.0 indicates a substantial risk. The exploit requires only a local logon with low privileges, meaning a local attacker could compromise Work in Process and gain full control. The EPSS score is below 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Given that local access is required, any host that an attacker can log into poses a realistic attack surface; the combination of confidentiality, integrity, and availability impacts and the relative ease of local exploitation places the vulnerability at a high threat level for affected environments.

Generated by OpenCVE AI on August 24, 2026 at 21:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Oracle patch available through the referenced Oracle security alert
  • Restrict network access to the Work in Process service, using firewalls or VLAN segmentation so only trusted hosts can reach it
  • Ensure that accounts used to run the Work in Process application have the minimum necessary permissions and are not granted broader privileges than required

Generated by OpenCVE AI on August 24, 2026 at 21:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Enables Full Control of Oracle Work in Process

Mon, 24 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation Enables Full Control of Oracle Work in Process
Weaknesses CWE-269

Fri, 21 Aug 2026 12:00:00 +0000

Type Values Removed Values Added
Title Local Attacker Compromise of Oracle Work in Process
Weaknesses CWE-284

Wed, 19 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Local Attacker Compromise of Oracle Work in Process
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in takeover of Oracle Work in Process. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-24T15:23:33.076Z

Reserved: 2026-07-14T14:54:48.732Z

Link: CVE-2026-62449

cve-icon Vulnrichment

Updated: 2026-08-24T15:13:03.189Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-18T21:17:01.607

Modified: 2026-08-31T13:43:22.733

Link: CVE-2026-62449

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:30:16Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control