Remote Code Execution Vulnerability in Oracle E-Business Suite Workflow Mailer
CVE-2026-60143
7.3HIGH
What is CVE-2026-60143?
The vulnerability in Oracle Workflow, part of the Oracle E-Business Suite, enables unauthenticated attackers with network access to exploit the Workflow Notification Mailer. This exploitable flaw permits unauthorized updates, inserts, or deletions of accessible data. Additionally, it poses a risk of unauthorized reads of sensitive data and can lead to partial denial of service scenarios, impacting the overall functionality of the Oracle Workflow. Comprehensive security measures are recommended to mitigate these risks.
Affected Version(s)
Oracle Workflow 12.2.3 <= 12.2.15