Sceawere
Vulnerability Detail
CVE-2026-70926UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Workflow SMTP Takeover Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Workflow
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-08-18T21:17:50.510Z",
"pubdate": "2026-08-18T21:17:50.510Z",
"executiveSummary": "A critical remote vulnerability exists within the Oracle Workflow product of Oracle E-Business Suite, specifically residing in the Workflow Notification Mailer component. This security flaw enables an unauthenticated threat actor with network access via the SMTP protocol to completely compromise the targeted Oracle Workflow installation. Successful exploitation results in a total system takeover, granting the attacker high-level control with severe implications for Confidentiality, Integrity, and Availability. The vulnerability yields a maximum CVSS 3.1 Base Score of 9.8, indicating extreme severity. Exploitation requires no user interaction, low attack complexity, and no prior authentication or privileges, making it highly accessible to external adversaries targeting exposed enterprise environments. Supported product versions 12.2.3 through 12.2.15 are affected. The risk implications include complete operational disruption, unauthorized data exposure, and full administrative compromise of the affected workflow infrastructure.",
"technicalDetails": "The vulnerability manifests within the Workflow Notification Mailer component of Oracle Workflow, part of Oracle E-Business Suite. The root cause stems from insecure handling and processing of incoming or internal SMTP communications, which allows an unauthenticated attacker leveraging network access via the SMTP protocol to inject malicious payloads or manipulate data structures handled by the mailer. Because the affected component fails to adequately validate or sanitize inputs processed through the mailer daemon, an attacker can abuse the mail processing logic to achieve arbitrary code execution or unauthorized command injection within the context of the application server. The attack flow begins when an external or network-positioned actor transmits a crafted SMTP message directly to the vulnerable Workflow Notification Mailer. Given that the attack vector is network-based (AV:N) and requires zero privileges (PR:N) alongside zero user interaction (UI:N), the malformed protocol traffic is processed automatically by the underlying mail handling routines. The low attack complexity (AC:L) ensures that standard, repeatable exploitation techniques can be leveraged without sophisticated race conditions or bespoke environmental prerequisites. Upon successful processing of the payload, the application executes the injected instructions with the privileges of the Oracle Workflow service account. Post-exploitation impact encompasses a full system takeover (S:U), allowing the adversary to pivot internally, alter critical workflow logic, exfiltrate sensitive enterprise data, or disrupt core business processes managed by Oracle E-Business Suite. Affected software versions strictly include Oracle Workflow versions 12.2.3 through 12.2.15."
}