A critical vulnerability (CVE-2026-46963) has been identified in Oracle Universal Work Queue, part of Oracle E-Business Suite. This vulnerability exists in the Work Provider Site Level Administration component and affects versions 12.2.3 to 12.2.15. A low-privileged attacker with network access via HTTP can exploit this vulnerability to compromise the Oracle Universal Work Queue, potentially leading to system takeover. While the vulnerability is specific to Oracle Universal Work Queue, successful exploitation may impact additional products due to scope change. The CVSS 3.1 base score is 9.9, indicating a critical severity level with high impact on confidentiality. Organizations using the affected versions of Oracle E-Business Suite should apply the latest security patches immediately to mitigate this risk. It is recommended to review Oracle's advisory for detailed mitigation steps and ensure all systems are up to date with the most recent security updates.
CRITICAL
CVSS 9.9
CVE-2026-46963
2026-08-25
Critical Vulnerability in Oracle Universal Work Queue (CVE-2026-46963)
A critical vulnerability (CVE-2026-46963) affects Oracle Universal Work Queue and Oracle E-Business Suite, allowing low-privileged attackers to take over the system via HTTP. CVSS 9.9. Patch immediately.