Vulnerability in Oracle E-Business Suite Workflow Loader Exposes Sensitive Data
CVE-2026-21959
4.9MEDIUM
What is CVE-2026-21959?
A vulnerability exists in the Oracle Workflow component of the Oracle E-Business Suite that permits a high-privileged attacker with network access via HTTP to compromise the system. This flaw enables the attacker to gain unauthorized access to critical and sensitive information within Oracle Workflow. Exploitation of the vulnerability can lead to a breach of confidentiality, allowing the attacker complete visibility and access to all data associated with Oracle Workflow without any necessary user interaction.
Affected Version(s)
Oracle Workflow 12.2.3 <= 12.2.15