Executive brief
A vulnerability exists in the Workflow Notification Mailer component of Oracle E-Business Suite, which manages automated business process communications. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain business data. Additionally, this could be used to disrupt the workflow service, potentially delaying critical business approvals or notifications.
Technical details
This vulnerability affects the Workflow Notification Mailer component within Oracle Workflow (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. A successful exploit allows an attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of data accessible to the Workflow component. Furthermore, the vulnerability can be leveraged to cause a partial denial of service (DoS) affecting the availability of the workflow system. The issue impacts versions 12.2.3 through 12.2.15 and was addressed in the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Corporation Oracle Workflow 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
- 2026-07-21: disclosed: CVE-2026-60575 was published to the NVD.