Executive brief
A vulnerability exists in the Oracle Workflow component of the Oracle E-Business Suite, which manages business process automation and email notifications. An unauthenticated attacker could potentially take full control of the workflow system by sending malicious communications via SMTP. A successful exploit could lead to the unauthorized access, modification, or deletion of sensitive business data and disruption of automated operations.
Technical details
This vulnerability affects the Workflow Notification Mailer component within Oracle Workflow (Oracle E-Business Suite). It is classified as a high-severity issue that allows an unauthenticated attacker with network access via SMTP to compromise the system. While the attack complexity is rated as high, a successful exploit grants the attacker full control over the Confidentiality, Integrity, and Availability of the Oracle Workflow product. The vulnerability impacts versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Workflow Notification Mailer 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Initial publication by Oracle and NVD