Junglewise Threat Intelligence

CVE-2026-62451: Oracle Work in Process unauthorized data access in Internal Operations

CVE-2026-62451 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle Work in Process. Vendors: Oracle.

Executive brief

A security vulnerability exists in the Internal Operations component of Oracle Work in Process, a module within the Oracle E-Business Suite used for managing manufacturing floor activities. An attacker with basic user credentials could exploit this flaw over the network to gain unauthorized access to sensitive manufacturing data. This could result in the theft, deletion, or modification of critical business information, potentially disrupting production schedules and compromising data integrity.

Technical details

This vulnerability affects the Internal Operations component of Oracle Work in Process within Oracle E-Business Suite versions 12.2.14 and 12.2.15. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation grants the attacker unauthorized 'create, delete, or modify' access to all accessible data within the Work in Process module, as well as full read access to critical data. The attack does not require user interaction and has high impacts on confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Work in Process (Oracle E-Business Suite) 12.2.14, 12.2.15

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-62451 by Oracle

References

Related threats