Executive brief
A vulnerability exists in the Oracle Universal Work Queue, a component of the Oracle E-Business Suite used for managing and distributing tasks across an organization. A remote attacker with basic user credentials could exploit this flaw to take full control of the work queue system. This could lead to the unauthorized access of sensitive business data, disruption of task management operations, and loss of data integrity.
Technical details
This vulnerability is located in the Work Provider Site Level Administration component of Oracle Universal Work Queue (part of Oracle E-Business Suite). It is classified under improper access control and privilege management (CWE-284, CWE-269). An attacker with low-privileged user access can exploit this over the network via HTTP, though the attack complexity is rated as high, suggesting specific timing or environmental conditions are required. Successful exploitation allows for a complete takeover of the Universal Work Queue, impacting confidentiality, integrity, and availability. Affected versions include 12.2.3 through 12.2.15.
Affected products
- Oracle Universal Work Queue 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Security Alert published