Junglewise Threat Intelligence

CVE-2026-46965: Oracle Universal Work Queue improper access control in Work Provider Site Level Administration

CVE-2026-46965 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Oracle Universal Work Queue. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Universal Work Queue, a component of the Oracle E-Business Suite used for managing and distributing tasks across an organization. An attacker with basic user credentials can exploit this flaw over the network to gain full control over the Work Queue system. This could lead to the unauthorized access of sensitive business data, disruption of task management operations, and total loss of system integrity.

Technical details

This vulnerability is classified as an improper access control or missing authentication issue (CWE-284, CWE-306) within the Work Provider Site Level Administration component of Oracle Universal Work Queue. It is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to achieve a complete takeover of the Oracle Universal Work Queue, impacting confidentiality, integrity, and availability. The vulnerability affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle Universal Work Queue 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats