Description
Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Workbenches). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Work in Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized data modification and access to critical data (confidentiality and integrity loss).
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an authentication bypass that allows an attacker with physical access to the network segment attached to the hardware where Oracle Work in Process runs to gain unrestricted access. Once accessed, the attacker can create, delete, or modify any data within the application, compromising both confidentiality and integrity of critical information. The flaw is classified as an access control weakness.

Affected Systems

Oracle Work in Process product in Oracle E‑Business Suite, versions 12.2.3 through 12.2.15, used in the Workbenches component. The vendor is Oracle Corporation.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 indicates a high risk level, while the EPSS score of less than 1% denotes a currently low likelihood of exploitation. The vulnerability is not listed in CISA KEV. The attack requires physical network access to the hardware where Oracle Work in Process executes; once accessed, the attacker can perform arbitrary data operations without authentication.

Generated by OpenCVE AI on September 20, 2026 at 07:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest security patch released by Oracle for Oracle Work in Process versions 12.2.3–12.2.15.
  • Segment and secure the physical network segment that connects to the Oracle Work in Process hardware, restricting access to authorized personnel only.
  • Enforce strict access control and least privilege on Oracle Work in Process, limiting user permissions to the minimum required for their role.
  • Monitor logs for unauthorized data modifications or creation events within Oracle Work in Process and enforce strict change‑management controls.

Generated by OpenCVE AI on September 20, 2026 at 07:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated Access to Oracle Work in Process via Physical Network Segment

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Fri, 18 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Title Oracle Work in Process Physical Access Data Compromise Vulnerability
Weaknesses CWE-284

Wed, 16 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Title Oracle Work in Process Physical Access Data Compromise Vulnerability
Weaknesses CWE-284

Tue, 15 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Workbenches). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Work in Process executes to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Work in Process accessible data as well as unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle work In Process
CPEs cpe:2.3:a:oracle:work_in_process:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle work In Process
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Oracle Work In Process
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-09-18T18:23:46.160Z

Reserved: 2026-08-31T15:40:57.361Z

Link: CVE-2026-83477

cve-icon Vulnrichment

Updated: 2026-09-18T18:14:54.668Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T20:18:55.473

Modified: 2026-09-18T19:17:06.797

Link: CVE-2026-83477

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T07:30:17Z

Weaknesses