Junglewise Threat Intelligence

CVE-2026-60780: Oracle Workflow unauthenticated compromise in Internal Operations

CVE-2026-60780 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Workflow. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle Workflow, a component of the Oracle E-Business Suite used to automate business processes and routing. An unauthenticated attacker could exploit this flaw over the network to gain full control of the Workflow system. This could lead to the unauthorized access, modification, or deletion of sensitive business data and the disruption of automated operations.

Technical details

A vulnerability in the Internal Operations component of Oracle Workflow (part of Oracle E-Business Suite) allows for a complete system takeover. The flaw is exploitable by an unauthenticated attacker via the SMTP network protocol. While the attack is considered difficult to execute (High Attack Complexity), a successful exploit results in a total loss of confidentiality, integrity, and availability. Affected versions include 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Workflow 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-60780
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats