CVE-2026-46966: Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration)
Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An authentication-partial, network-exploitable vulnerability exists in the Work Provider Site Level Administration component of Oracle Universal Work Queue, part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. An attacker with a low-privileged account and HTTP network access can exploit this under specific conditions to fully compromise the affected system. Successful exploitation results in complete loss of confidentiality, integrity, and availability, effectively a full takeover of the Oracle Universal Work Queue instance. HarborGuard is tracking this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix version.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: CVE-2026-46966 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images layering Oracle E-Business Suite components. Any image found running an affected version of Oracle Universal Work Queue (12.2.3 through 12.2.15) is flagged immediately.
AvailableHarborGuard scores this finding at CVSS 7.5 HIGH using the published v3.1 vector, and that score is available as a baseline for per-environment compliance policy weighting. Triage routing capability is available to direct findings to the appropriate team inbox within each customer organization based on policy configuration.
AvailableBecause Oracle has not yet published a fix version for CVE-2026-46966, HarborGuard re-checks the advisory each ingest cycle and will make a patched-image rebuild available automatically once Oracle ships a patch. For customers who opt into auto-remediation, the rebuild, regression test run, and PR against affected workloads will trigger without manual intervention the moment a fix version becomes available upstream.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the Oracle Universal Work Queue service over the network via HTTP; no local or physical access pathway is described.
- AuthenticationRequired
A low-privileged account is sufficient, but the attacker must hold valid credentials before the attack can proceed.
- Victim interactionNot required
No user interaction is needed; the attacker can carry out the exploit without involving any other party.
- Attack complexityDetail
Attack complexity is rated HIGH, meaning the attacker must meet specific environmental conditions or timing constraints beyond basic network access to trigger the vulnerability reliably.
Blast Radius
- A successful attacker reads all data accessible to the Oracle Universal Work Queue application, including work item records, user data, and configuration secrets.
- The attacker can modify or delete persisted work queue data, assignments, and site-level administration settings.
- The attacker can crash or render the Oracle Universal Work Queue service unavailable, disrupting any business processes that depend on it.
- The combination of full confidentiality, integrity, and availability impact constitutes a complete takeover of the affected Oracle Universal Work Queue instance.
How HarborGuard Handles This
Available on HarborGuard: this CVE is actively monitored with no fix version currently published by Oracle. Images running Oracle Universal Work Queue versions 12.2.3 through 12.2.15 are flagged automatically within minutes of scan ingestion. While no upstream patch exists, customers can apply compensating controls using HarborGuard network policy recommendations: restricting HTTP ingress to the Work Provider Site Level Administration component to known, trusted source CIDRs via network policy isolation, and enforcing egress filtering to limit lateral movement if the service is compromised. Because attack complexity is HIGH (AC:H) and authentication is required (PR:L), restricting account provisioning and tightening network exposure meaningfully reduces exploitation likelihood in the interim. HarborGuard will re-check the Oracle advisory each ingest cycle; for customers who opt into auto-remediation, a patched-image rebuild, regression test run, and PR against affected workloads will be triggered automatically the moment Oracle publishes a fix version, with no manual intervention required.
- Oracle Corporation / Oracle Universal Work Queue≤ 12.2.15
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H