Junglewise Threat Intelligence

CVE-2026-60701: Oracle Universal Work Queue takeover in Work Provider Site Level Administration

CVE-2026-60701 · Severity: medium · CVSS 6.6 · Published 2026-07-21

Technologies: Oracle Universal Work Queue. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle Universal Work Queue component of Oracle E-Business Suite could allow a high-privileged user to take full control of the application. Oracle Universal Work Queue is used to manage and distribute tasks across an organization; a compromise could lead to the unauthorized access, modification, or deletion of business task data. While the attack requires significant privileges and specific conditions to execute, a successful exploit impacts the confidentiality, integrity, and availability of the system.

Technical details

This vulnerability exists in the Work Provider Site Level Administration component of Oracle Universal Work Queue (part of Oracle E-Business Suite). It is classified as a 'takeover' vulnerability, though the specific CWE is not provided in the advisory. The attack vector is network-based via HTTP, but exploitation is considered difficult (Attack Complexity: High) and requires high-privileged credentials (Privileges Required: High). If successfully exploited, an attacker can achieve full compromise of the Universal Work Queue, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Universal Work Queue 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats