Junglewise Threat Intelligence

CVE-2026-70926: Oracle E-Business Suite Workflow remote code execution via SMTP

CVE-2026-70926 · Severity: critical · CVSS 9.8 · Published 2026-08-18

Technologies: Oracle Workflow, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

Oracle E-Business Suite includes a Workflow Notification Mailer component that processes incoming email messages. An unauthenticated attacker with network access to the SMTP interface can exploit this vulnerability to gain complete control of the Workflow system, compromising confidentiality, integrity, and availability of business-critical workflow data and operations.

Technical details

This vulnerability in the Workflow Notification Mailer component of Oracle E-Business Suite allows unauthenticated remote code execution via the SMTP protocol. The attack requires only network access to the SMTP interface and no user interaction or authentication. Successful exploitation results in complete compromise of the Oracle Workflow system, with CVSS 3.1 score of 9.8 indicating critical severity across all impact categories (confidentiality, integrity, availability). The vulnerability affects versions 12.2.3 through 12.2.15. Patch availability and remediation steps should be obtained from Oracle's official security advisory.

Affected products

  • Oracle E-Business Suite 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats