Junglewise Threat Intelligence

CVE-2026-60700: Oracle E-Business Suite data compromise in Universal Work Queue

CVE-2026-60700 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle Universal Work Queue component of the Oracle E-Business Suite, which is used to manage and distribute tasks across an organization. An attacker could trick a legitimate user into performing an action that allows the attacker to view, modify, or delete sensitive business data. This could lead to a significant breach of confidential information or the corruption of critical operational records.

Technical details

This vulnerability affects the UWQ Server Issues component of Oracle Universal Work Queue in Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is an easily exploitable flaw that allows an unauthenticated attacker with network access via HTTP to compromise the application. The attack requires human interaction (User Interaction: Required), suggesting a vulnerability class such as Cross-Site Request Forgery (CSRF) or a similar client-side injection. Successful exploitation grants the attacker high confidentiality and integrity impacts, allowing for the unauthorized creation, deletion, or modification of critical data. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Universal Work Queue 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References