Executive brief
A vulnerability exists in the Workflow Notification Mailer component of Oracle E-Business Suite, which manages automated business process communications. A highly privileged attacker with existing access to the underlying server infrastructure could exploit this flaw to cause a total system crash or service outage. Additionally, the attacker could gain unauthorized access to read, modify, or delete specific business data managed by the workflow system.
Technical details
This vulnerability affects the Workflow Notification Mailer component within Oracle Workflow (Oracle E-Business Suite). It is classified as difficult to exploit (High Attack Complexity) and requires the attacker to have high-level privileges and local logon access to the infrastructure where Oracle Workflow executes. Successful exploitation allows an attacker to cause a complete denial-of-service (hang or repeatable crash) of the Workflow service. Furthermore, it permits unauthorized read access to a subset of data and unauthorized update, insert, or delete access to specific data accessible by the Workflow engine. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle E-Business Suite (Oracle Workflow) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
- 2026-07-21: disclosed