Vulnerability in Oracle Workflow of Oracle E-Business Suite
CVE-2026-60149

5.2MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-60149?

This vulnerability in the Oracle Workflow component of Oracle E-Business Suite exposes the system to potential compromises by high-privileged attackers. If exploited, it could lead to serious issues, allowing unauthorized updates, inserts, or deletions of accessible data, along with unauthorized read access to certain datasets. Attackers with logon capabilities and requisite permissions could disrupt the Oracle Workflow's operations, resulting in repeated system hangs or crashes, ultimately impacting the availability of the service.

Affected Version(s)

Oracle Workflow 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
5.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.