Junglewise Threat Intelligence

CVE-2026-60144: Oracle E-Business Suite data manipulation in Oracle Workflow

CVE-2026-60144 · Severity: low · CVSS 3.6 · Published 2026-07-21

Technologies: Oracle E-Business Suite Workflow. Vendors: Oracle.

Executive brief

Oracle Workflow is a component of the Oracle E-Business Suite used to automate business processes and manage notifications. A vulnerability in the Workflow Notification Mailer could allow an employee or contractor with existing access to the underlying server to tamper with workflow data or cause the service to become partially unavailable. While the impact is limited to data integrity and service availability, it could disrupt internal business approvals and automated tasks.

Technical details

A vulnerability exists in the Workflow Notification Mailer component of Oracle Workflow (versions 12.2.3 through 12.2.15). The flaw is characterized by a high complexity of exploitation and requires the attacker to have local logon credentials to the infrastructure where the software executes. If successfully exploited, an attacker with low privileges can perform unauthorized updates, insertions, or deletions of data accessible to Oracle Workflow. Additionally, the attacker can cause a partial denial of service (DoS) affecting the availability of the workflow engine. The vulnerability does not appear to impact data confidentiality. Patches are typically released via the Oracle Critical Patch Update (CPU) program.

Affected products

  • Oracle E-Business Suite (Oracle Workflow) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle via July 2026 CPU

References

Related threats