Junglewise Threat Intelligence

CVE-2026-61278: Oracle Workflow Notification Mailer unauthorized data access and DoS

CVE-2026-61278 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle Workflow component of the Oracle E-Business Suite, which manages business process automation and email notifications. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain business data. Additionally, an exploit could cause a partial service outage, disrupting automated business workflows and communication.

Technical details

This vulnerability affects the Workflow Notification Mailer component within Oracle Workflow (part of Oracle E-Business Suite). It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can achieve unauthorized read, update, insert, or delete access to a subset of data accessible to Oracle Workflow. Furthermore, the exploit can result in a partial denial of service (DoS) of the workflow engine. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Workflow Notification Mailer 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats