Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4347 articles · 196413 vulns · 36/41 feeds (7d)
← Back to list
9.8
CVE-2026-70926PATCHED
oracle · oracle workflow

CVE-2026-70926: Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supp

Description

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Notification Mailer). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Workflow. Successful attacks of this vulnerability can result in takeover of Oracle Workflow. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Products

VendorProductVersions
oracleoracle workflow12.2.3

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
oraclee-businesscert_advisory90%

References

  • https://www.oracle.com/security-alerts/cspuaug2026.html(vendor-advisory)

Related News (3 articles)

Tier C
Qualys Blog4d ago
Oracle Critical Patch Update, August 2026 Security Update Review
→ No new info (linked only)
Tier B
BSI Advisories5d ago
[NEU] [hoch] Oracle E-Business Suite: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB5d ago
CVE-2026-70926 | Oracle Workflow up to 12.2.15 Workflow Notification Mailer improper authentication
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://www.oracle.com/security-alerts/cspuaug2026.html
PublishedAug 18, 2026
Trending Score35
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-47057
CVE-2026-47057: Vulnerability in Oracle Java SE (component: Scripting). Supported versions that are affected are Oracle Java SE: 8u491,
Trending: 38
HIGHCVE-2026-47063
CVE-2026-47063: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 38
CRITICALCVE-2026-60782
CVE-2026-60782: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versi
Trending: 35
MEDIUMCVE-2026-47021
CVE-2026-47021: Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE
Trending: 35
MEDIUMCVE-2026-47027
CVE-2026-47027: Vulnerability in Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 8u491,
Trending: 35

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 18, 2026
Discovered by ZDM
Aug 18, 2026
Patch Available
Aug 22, 2026