CVE-2026-46965
Oracle · E-Business Suite (Universal Work Queue)
A high-severity vulnerability exists within the Work Provider Site Level Administration component of the Oracle E-Business Suite Universal Work Queue.
Executive summary
An authenticated attacker could exploit a vulnerability in the Oracle E-Business Suite Universal Work Queue component to perform unauthorized site-level administrative actions.
Vulnerability
The vulnerability exists in the Work Provider Site Level Administration component, requiring an authenticated attacker to exploit the lack of proper validation at the administrative level.
Business impact
A CVSS score of 8.8 underscores the significant risk of administrative-level compromise. An attacker exploiting this could potentially gain full control over the Universal Work Queue, resulting in severe data loss or manipulation of critical business processes.
Remediation
Immediate Action: Apply the relevant security patch from Oracle to remediate the vulnerability in the Work Provider Site Level Administration component.
Proactive Monitoring: Audit administrative access logs and monitor for unauthorized changes to site-level configuration settings.
Compensating Controls: Enforce multi-factor authentication (MFA) for all administrative accounts to mitigate the risk of credential misuse.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Given the administrative scope of this vulnerability, immediate remediation is required. Security teams should verify their current version against the vendor advisory and deploy the necessary patches to protect the E-Business Suite.