HIGH 7.5

CVE-2026-46966: Oracle Universal Work Queue Privilege Escalation (CVSS 7.5)

A vulnerability in Oracle's Universal Work Queue component of E-Business Suite allows a low-privileged user with network access to take over the application. The flaw exists in the site-level administration features and requires specific difficult-to-exploit conditions, but successful compromise results in complete loss of confidentiality, integrity, and availability for the affected system. This affects E-Business Suite versions 12.2.3 through 12.2.15.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-269, CWE-284, CWE-306
Affected products
1 configuration(s)
Published / Modified
2026-06-17 / 2026-06-18

NVD description (verbatim)

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-46966 is an improper access control vulnerability in the Oracle Universal Work Queue Work Provider Site Level Administration component. The vulnerability resides in inadequate privilege validation mechanisms (CWE-269, CWE-284) combined with missing authentication checks (CWE-306) that permit an authenticated attacker to escalate their actions beyond their authorized scope. Attack surface is limited to HTTP-accessible endpoints, and exploitation requires specific preconditions (reflected in the CVSS AC:H rating), but once exploited grants full system compromise capabilities to the attacker.

Business impact

Compromise of Universal Work Queue affects workforce management and queue processing across the E-Business Suite environment. An attacker gaining control could manipulate work assignments, intercept sensitive workflow data, disrupt service availability for dependent business processes, and potentially pivot to other EBS modules sharing the same authentication realm. For organizations relying on UWQ for critical operational workflows, this represents a path to broad business process disruption.

Affected systems

Oracle E-Business Suite versions 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, and 12.2.15 are in scope. Organizations running Universal Work Queue within any of these E-Business Suite releases should inventory affected instances, with particular attention to production and critical-path systems.

Exploitability

The vulnerability rates as 'difficult to exploit' per the CVSS scoring (AC:H), meaning specific system or attacker conditions must align for successful exploitation. However, this is not a preventive factor—it indicates complexity rather than infeasibility. An attacker with low-privilege network credentials and knowledge of the administration interface topology could overcome these barriers. The requirement for low-privilege authentication (PR:L) narrows the attacker pool to insiders, former employees, or accounts obtained through credential compromise—a realistic threat in enterprise environments.

Remediation

Patching is the primary remediation path. Organizations should apply Oracle's Critical Patch Update (CPU) or cumulative patches released for the affected E-Business Suite versions. Interim controls include restricting network access to Work Provider Site Level Administration endpoints via firewall rules, implementing network segmentation to limit attacker network access (AV:N), enforcing multi-factor authentication for E-Business Suite accounts, and increasing monitoring of UWQ administrative function calls.

Patch guidance

Consult Oracle's security advisories and Critical Patch Update notices for the specific patch or bundle applicable to your E-Business Suite version. Verify patch applicability through Oracle's support portal before deployment. Patches must be tested in a non-production environment, with particular focus on work queue functionality, user authentication workflows, and dependent integrations. Schedule patching during a controlled maintenance window, as E-Business Suite patching can affect system availability.

Detection guidance

Monitor application logs for failed authentication attempts targeting Work Provider Site Level Administration features and unusual privilege escalation activities by low-privileged accounts. Watch HTTP request patterns for attempts to access administrative endpoints from unusual source IPs or at unusual times. Search for unexpected changes to work queue configurations, user assignments, or routing rules that may indicate post-exploitation activity. Consider deploying application-level monitoring rules that flag attempts to access protected administration endpoints by non-administrative accounts.

Why prioritize this

This vulnerability merits high-priority remediation due to the CVSS 7.5 score, widespread E-Business Suite deployment in enterprise environments, and the complete system compromise potential (C:H, I:H, A:H impacts). While exploit complexity is elevated, the requirement for only low-privilege access and the critical nature of E-Business Suite in many organizations justifies immediate planning and resource allocation. The vulnerability is not yet in active exploitation (KEV status false), providing a window for proactive patching before threat actors develop reliable exploits.

Risk score, explained

The CVSS 3.1 score of 7.5 reflects a high-risk vulnerability: network-accessible attack vector, difficult but plausible exploitation complexity, low-privilege attacker requirement, and complete confidentiality, integrity, and availability impacts. The 'difficult to exploit' rating prevents a critical score (8.0+), but does not materially reduce organizational risk given the prevalence of credential compromise and insider threat scenarios. The score appropriately captures the severity of full system takeover balanced against realistic exploitation barriers.

Frequently asked questions

Do I need to patch immediately if this vulnerability hasn't been exploited in the wild yet?

Yes. The KEV status being false indicates the vulnerability is not actively weaponized at this moment, but this is a transient condition. Low-privilege access is a common attacker foothold, and exploit code may emerge rapidly once public awareness increases. Immediate patching prioritization reduces risk from both opportunistic and sophisticated threat actors.

Can network segmentation alone protect us if we cannot patch immediately?

Network segmentation significantly reduces risk by limiting attacker network access (the AV:N component), but does not eliminate it. If an attacker already has low-privilege credentials or network access to the UWQ administration interface—whether through VPN, internal networks, or compromised accounts—segmentation may not prevent exploitation. Segmentation is a critical interim control but should not delay patching planning.

How does the 'difficult to exploit' rating affect our patching timeline?

Difficult exploitation (AC:H) means exploitation requires specific conditions or extensive attacker knowledge, not that it is impossible. In a targeted attack scenario against high-value systems, motivated attackers invest the time to overcome these barriers. For enterprise security, this should inform your patch sequencing—prioritize assets where low-privilege attackers are most likely or where business impact is highest—but should not extend patch timelines indefinitely.

Are there other E-Business Suite components at risk if our UWQ is compromised?

Yes. A successful UWQ compromise provides an attacker with valid E-Business Suite credentials and deep system access, enabling lateral movement to other modules sharing the same authentication realm and database connections. Compartmentalization and monitoring of cross-module activity are important secondary controls during the patching window.

This analysis is based on the published CVE details and Oracle advisories as of the modification date. Patch version numbers, specific remediation steps, and Oracle support timelines should be verified directly with Oracle Security Alerts and your vendor support contract. Exploitation feasibility and attack likelihood are subject to change as threat intelligence evolves. This assessment does not constitute professional advice; organizations should consult internal risk management processes and security teams before making patching decisions. SEC.co does not create, test, or distribute exploit code and does not engage in offensive security activities targeting these vulnerabilities. Source: NVD (public-domain), retrieved 2026-07-26. Analysis generated by SEC.co (claude-haiku-4-5).