HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46964Published Modified CNA oracle

CVE-2026-46964: Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration)

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. While the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Metrics

CVSS v3.1
9.9
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A critical-severity, remotely exploitable vulnerability exists in the Work Provider Site Level Administration component of Oracle Universal Work Queue, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. An attacker with any low-privilege account and HTTP network access can exploit this flaw without any additional interaction from a victim. Successful exploitation results in a full takeover of Oracle Universal Work Queue, with scope change meaning the impact can spill over into other products sharing the environment. No fix version has been published by Oracle; HarborGuard is tracking the advisory for patch availability.

HarborGuard Coverage

Detection

Detection for CVE-2026-46964 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer container images, including custom-built images that bundle Oracle E-Business Suite components. Any image carrying an affected version of Oracle Universal Work Queue (12.2.3 through 12.2.15) will surface in the findings dashboard automatically.

Available
Triage

HarborGuard scores this finding at CVSS 9.9 Critical and can weight it further against each environment's compliance policy to prioritize routing. Findings are directed to the appropriate team inbox within each customer organization based on configured ownership rules, so the right engineers see this alert without manual triage.

Available
Patch

Because no upstream fix version has been published, HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available the moment Oracle ships a remediated release. In the interim, customers can apply compensating controls through HarborGuard's network-policy recommendations to restrict HTTP access to the affected component to authorized principals only.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle Universal Work Queue service over the network via HTTP; there is no requirement for local or physical access.

  • AuthenticationRequired

    Any low-privilege account is sufficient; the attacker does not need administrative credentials, but some form of authenticated access to the application is required.

  • Victim interactionNot required

    The exploit completes without any action from another user; no social engineering or victim click is needed.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special timing, race conditions, or environmental prerequisites beyond network access and a low-privilege account.

Blast Radius

  • A successful attacker gains full control over Oracle Universal Work Queue, reading all stored work-queue data including task records, user assignments, and configuration details.
  • The attacker can modify or delete persisted work-queue rows and administrative configuration, disrupting business-process routing and data integrity.
  • The affected service can be crashed or rendered unavailable, halting work distribution across all queues.
  • Because the CVSS scope is changed, the attacker can pivot to compromise additional Oracle E-Business Suite products co-hosted in the same environment, extending impact beyond the initial target.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-46964 is active for all customer environments scanning images that include Oracle Universal Work Queue 12.2.3 through 12.2.15, with findings surfaced at Critical severity. Because Oracle has not yet published a remediated version, no patched-image rebuild is currently available. HarborGuard re-checks the advisory on every ingest cycle; when Oracle releases a fix, a rebuilt image becomes available immediately, and customers with auto-remediation enabled will receive a regression-tested rebuild and an auto-opened PR against affected workloads. While no patch exists, recommended compensating controls include applying network policies that restrict HTTP access to the Work Provider Site Level Administration component to the smallest possible set of authenticated principals, enabling egress filtering to limit lateral movement if a compromise occurs, and auditing existing low-privilege accounts with access to the affected component to reduce the attacker's pool of usable credentials.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Universal Work Queue
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References