Vulnerability in Oracle E-Business Suite's Universal Work Queue Component
CVE-2026-46965

8.8HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46965?

A security flaw in the Oracle Universal Work Queue component of Oracle E-Business Suite poses a risk to user systems, enabling unauthorized low-privileged attackers with network access via HTTP to potentially take control of the system. This vulnerability affects several versions of the product (12.2.3 to 12.2.15) and can lead to significant operational disruptions, highlighting the need for immediate attention and remediation.

Affected Version(s)

Oracle Universal Work Queue 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.