Junglewise Threat Intelligence

CVE-2026-70931: Oracle E-Business Suite Workflow unauthorized data access and denial of service

CVE-2026-70931 · Severity: high · CVSS 8.1 · Published 2026-08-18

Technologies: Oracle Workflow, Oracle E-Business Suite Workflow. Vendors: Oracle.

Executive brief

Oracle E-Business Suite Workflow handles email notifications and critical business process communications. A low-privileged network attacker can exploit this vulnerability to modify or delete sensitive business data, or crash the entire Workflow system causing operational disruption. This affects organizations relying on Workflow for order management, approvals, and compliance auditing.

Technical details

This is an integrity and availability vulnerability in the Workflow Notification Mailer component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. The vulnerability is easily exploitable via HTTP by a low-privileged authenticated attacker with network access. Successful exploitation allows unauthorized creation, deletion, or modification of critical data within Oracle Workflow, or the ability to cause repeated denial-of-service conditions (hangs or crashes). The attack requires network connectivity and valid credentials but no user interaction. Patches are expected from Oracle's Critical Patch Update program.

Affected products

  • Oracle E-Business Suite Workflow 12.2.3 to 12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats