Junglewise Threat Intelligence

CVE-2026-70927: Oracle E-Business Suite Workflow Notification Mailer denial of service

CVE-2026-70927 · Severity: high · CVSS 7.5 · Published 2026-08-18

Technologies: Oracle Workflow, Oracle E-Business Suite Workflow. Vendors: Oracle.

Executive brief

A vulnerability in Oracle E-Business Suite's Workflow Notification Mailer component allows an unauthenticated attacker over the network to crash or hang the workflow system, disrupting business processes that depend on notifications and approvals. This affects organizations using the Workflow product for task routing and notifications, resulting in operational downtime and inability to process time-sensitive workflows.

Technical details

The vulnerability is a denial-of-service condition in the Workflow Notification Mailer component of Oracle E-Business Suite, versions 12.2.3–12.2.15. It is easily exploitable via unauthenticated HTTP requests over the network, requiring no user interaction or authentication. Successful exploitation causes the Workflow component to hang or crash repeatedly, rendering it unavailable. The attack vector is network-based with low complexity, and the impact is complete availability loss of the affected service. Patch availability is not explicitly confirmed in the advisory.

Affected products

  • Oracle E-Business Suite Workflow 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed
  • 2026-08-18: advisory: CVE-2026-70927

References

Related threats