Junglewise Threat Intelligence

CVE-2026-83477: Oracle Work in Process unauthorized data access in Workbenches

CVE-2026-83477 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle Work in Process. Vendors: Oracle.

Executive brief

Oracle Work in Process is a critical component of Oracle E-Business Suite that manages manufacturing workflows and production data. An attacker with physical access to the network segment containing the application server can exploit this vulnerability to read, modify, or delete sensitive manufacturing and business data without authentication. This could lead to disruption of production operations, unauthorized access to confidential business information, and compliance violations.

Technical details

This is an easily exploitable vulnerability in the Workbenches component of Oracle Work in Process that allows an unauthenticated attacker to compromise confidentiality and integrity of the application. The attack requires adjacent network access (physical connection to the communication segment where the server executes) but no user interaction or authentication. Successful exploitation results in unauthorized creation, deletion, or modification of critical manufacturing data or complete read access to all Work in Process accessible data. The root cause and specific vulnerable component are not disclosed in available public sources. Patches are expected as part of Oracle's regular security update cycle for E-Business Suite versions 12.2.3 through 12.2.15.

Affected products

  • Oracle Work in Process 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats