Executive brief
Oracle Business Process Management Suite, a platform used by organizations to automate and manage business workflows, contains a critical security vulnerability in its Human Workflow component. An attacker with low-level access to the network can exploit this flaw to take complete control of the system. This could lead to the theft of sensitive business data, disruption of automated operations, and potential unauthorized access to other connected corporate systems.
Technical details
A vulnerability in the Human Workflow component of Oracle Business Process Management Suite (versions 12.2.1.4.0 and 14.1.2.0.0) allows for unauthorized takeover of the application. The flaw is easily exploitable by a low-privileged attacker with network access using the T3 or IIOP protocols. The vulnerability is notable for a 'scope change' (CVSS S:C), meaning a successful exploit can impact security beyond the immediate Business Process Management environment to other integrated products. Oracle has addressed this in the July 2026 Critical Patch Update.
Affected products
- Oracle Business Process Management Suite 12.2.1.4.0, 14.1.2.0.0
Timeline
- 2026-07-21: advisory: Initial disclosure by Oracle