Vulnerability in Oracle E-Business Suite Work Provider Site Level Administration
CVE-2026-46824

9.9CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
28 May 2026

What is CVE-2026-46824?

A security vulnerability exists in the Oracle Universal Work Queue component of Oracle E-Business Suite. This weakness enables an attacker with low-level privileges and network access through HTTP to exploit the application. While primarily impacting the Universal Work Queue, successful exploitation could extend to other interconnected products and systems, resulting in potential compromises and access to sensitive data. Prompt updates and security measures are highly recommended to mitigate risks associated with this vulnerability.

Affected Version(s)

Oracle Universal Work Queue 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.