Executive brief
A critical vulnerability exists in the Oracle Universal Work Queue, a component of the Oracle E-Business Suite used for managing agent tasks and workflows. A low-privileged user can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive business data, disruption of operations, and potential unauthorized access to other connected Oracle products.
Technical details
This vulnerability is classified as an improper access control issue (CWE-284) within the Work Provider Site Level Administration component of Oracle Universal Work Queue. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw is particularly severe because it involves a 'scope change' (CVSS S:C), meaning a successful compromise of the Universal Work Queue can be used to attack or impact other components of the Oracle E-Business Suite. Exploitation can result in a total loss of confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.
Affected products
- Oracle Universal Work Queue 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published