CVE-2026-21959: Medium severity Oracle E-Business Suite Workflow vulnerability

Published Jan 20, 2026
·
Updated

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Workflow accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).

Affected Software

2 affected components
Oracle E-Business Suite Workflow>=12.2.3<=12.2.15
Oracle Workflow>=12.2.3<=12.2.15

Event History

Jan 20, 2026
CVE Published
via MITRE·09:56 PM
Data Sourced
via MITRE·09:56 PM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 19, 58052
Event
via FIRST·02:49 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-21959?

CVE-2026-21959 is considered to be an easily exploitable vulnerability with high severity, as it allows high privileged attackers to compromise Oracle Workflow.

2

How do I fix CVE-2026-21959?

To remediate CVE-2026-21959, apply the latest security patches provided by Oracle for the affected versions of Oracle E-Business Suite Workflow.

3

Which versions are affected by CVE-2026-21959?

CVE-2026-21959 affects Oracle E-Business Suite Workflow versions 12.2.3 to 12.2.15.

4

Who is impacted by CVE-2026-21959?

Organizations using Oracle E-Business Suite Workflow within the specified versions are at risk due to CVE-2026-21959.

5

What component is vulnerable in CVE-2026-21959?

CVE-2026-21959 specifically affects the Workflow Loader component of Oracle Workflow in Oracle E-Business Suite.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203