CVE-2026-60830: Medium severity Oracle Oracle E-Business Suite (Worklist) vulnerability
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Workflow accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to Oracle Workflow (Worklist) HTTP endpoints so low-privileged attackers cannot reach them over the network.
Event History
Frequently Asked Questions
Which deployments are affected?
Affected supported versions are Oracle E-Business Suite Oracle Workflow Worklist versions 12.2.3 through 12.2.15.
What access does an attacker need to exploit this issue?
An attacker needs network access to the target over HTTP and low-privileged access. No user interaction is required, and the attack complexity is low.
What is the potential impact of successful exploitation?
Successful exploitation can expose critical data or provide access to all data accessible through Oracle Workflow. The documented impact is confidentiality-only; integrity and availability impacts are not listed.