Junglewise Threat Intelligence

CVE-2026-46963: Oracle Universal Work Queue improper access control in Work Provider Site Level Administration

CVE-2026-46963 · Severity: critical · CVSS 9.9 · Published 2026-06-17

Technologies: Oracle Universal Work Queue. Vendors: Oracle.

Executive brief

A critical vulnerability exists in the Oracle Universal Work Queue, a component of the Oracle E-Business Suite used for managing agent tasks and workflows. A low-privileged user can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive business data, disruption of operations, and potential unauthorized access to other connected Oracle products.

Technical details

This vulnerability is classified as an improper access control issue (CWE-284) within the Work Provider Site Level Administration component of Oracle Universal Work Queue. It is easily exploitable by a low-privileged attacker with network access via HTTP. The flaw is particularly severe because it involves a 'scope change' (CVSS S:C), meaning a successful compromise of the Universal Work Queue can be used to attack or impact other components of the Oracle E-Business Suite. Exploitation can result in a total loss of confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Universal Work Queue 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle Critical Patch Update published

References

Related threats