CVE-2026-62462

8.8

Oracle · Oracle Work in Process

A vulnerability in the Internal Operations component of Oracle Work in Process allows an authenticated attacker with network access to achieve a full system takeover.

Executive summary

An authenticated, high-severity vulnerability in Oracle Work in Process permits remote attackers to achieve unauthorized system takeover.

Vulnerability

This is an easily exploitable vulnerability where an attacker with low privileges can leverage network access via HTTP to compromise the application. The flaw exists within the Internal Operations component and grants the attacker full control over the affected software.

Business impact

Successful exploitation of this vulnerability results in a complete compromise of the Oracle Work in Process environment. With a CVSS score of 8.8, the business impact includes the potential for unauthorized access to sensitive production data, disruption of manufacturing workflows, and a total loss of system integrity.

Remediation

Immediate Action: Apply the security patches provided in the August 2026 Oracle Critical Patch Update advisory.

Proactive Monitoring: Review application access logs for anomalous behavior or unauthorized administrative actions performed by low-privileged accounts.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall to block malicious HTTP requests targeting the vulnerable component.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The risk posed by this vulnerability is significant, and immediate patching is required to prevent unauthorized system compromise. Organizations running Oracle Work in Process should update their systems according to the vendor guidelines to ensure business continuity and data security.

More Oracle CVEs