Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cspuaug2026.html |
|
History
Sat, 22 Aug 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote SMTP Exploitation of Oracle Workflow Leads to Full System Compromise |
Sat, 22 Aug 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SMTP Remote Code Execution in Oracle Workflow Notification Mailer | |
| Weaknesses | CWE-20 CWE-77 |
Sat, 22 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-306 | |
| Metrics |
ssvc
|
Fri, 21 Aug 2026 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SMTP Remote Code Execution in Oracle Workflow Notification Mailer | |
| Weaknesses | CWE-20 CWE-77 |
Thu, 20 Aug 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SMTP Exploit in Oracle Workflow Notification Mailer | |
| Weaknesses | CWE-284 CWE-287 |
Wed, 19 Aug 2026 04:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated SMTP Exploit in Oracle Workflow Notification Mailer | |
| Weaknesses | CWE-284 CWE-287 |
Tue, 18 Aug 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). | |
| First Time appeared |
Oracle
Oracle workflow |
|
| CPEs | cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle workflow |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published: 2026-08-18T21:02:33.056Z
Updated: 2026-08-22T02:42:23.375Z
Reserved: 2026-08-04T22:06:34.606Z
Link: CVE-2026-70926
Updated: 2026-08-22T02:42:16.948Z
Status : Awaiting Analysis
Published: 2026-08-18T21:17:50.510
Modified: 2026-08-22T03:16:23.237
Link: CVE-2026-70926
No data.