Junglewise Threat Intelligence

CVE-2026-60997: Oracle Universal Work Queue data compromise in Non-Media Integration

CVE-2026-60997 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle Universal Work Queue, a component of the Oracle E-Business Suite used to manage and prioritize agent tasks. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive business data. This could result in the theft, modification, or deletion of critical work records and organizational information.

Technical details

This vulnerability affects the Non-Media Integration component of Oracle Universal Work Queue within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires only low-privileged user authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve unauthorized creation, deletion, or modification of critical data, as well as gain complete read access to all data managed by the Universal Work Queue. The exploit does not require user interaction and has high impacts on confidentiality and integrity, though it does not directly impact service availability.

Affected products

  • Oracle Corporation Universal Work Queue 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
  • 2026-07-21: disclosed: Initial NVD publication date.

References