CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-46963

Critical · CVSS 9.9

Oracle Universal Work Queue (Oracle E-Business Suite) — Improper Access Control / Unauthorized Access leading to full product takeover (CWE-284)

CVSS
9.9
nvd
EPSS
KEV
No
Class
other
CWE-284

Description

Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. While the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Search profile — drives PoC discovery

Symbols Work Provider Site Level AdministrationOracle Universal Work QueueUWQEBSOracleEBS12.2.312.2.15CSPUJUN2026
Keywords CVE-2026-46963Oracle Universal Work QueueOracle EBS exploitWork Provider Site Level AdministrationOracle E-Business Suite 12.2 RCEEBS UWQ vulnerabilityOracle EBS access control bypassCVE-2026-46963 PoCOracle EBS takeoverCWE-284 Oracle EBS
Versions: 12.2.3 - 12.2.15

References

Status: enriched · ingested 2026-06-19T00:00:04.000Z · profiled 2026-06-19T00:30:04.000Z