CVE-2026-22014 is a vulnerability in the Oracle User Management component of Oracle E-Business Suite, affecting versions 12.2.7 through 12.2.15. The flaw exists within the Workflow and Business Events functionality and enables unauthorized data access and modification by high-privileged attackers. This represents a moderate risk to organizations running affected versions of Oracle E-Business Suite. The vulnerability has a CVSS 3.1 base score of 3.8 (LOW severity) with a network-based attack vector that requires high privilege credentials and no user interaction. Successful exploitation allows attackers to read a subset of User Management data and perform unauthorized updates, insertions, and deletions to accessible data. The low attack complexity indicates the vulnerability is straightforward to exploit by those with the necessary privileges. There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the CISA Known Exploited Vulnerabilities list, and community attention remains minimal based on the EPSS score of 0.00023. Organizations should prioritize patching based on asset criticality rather than immediate threat response, though timely remediation is still recommended to prevent potential abuse by insider threats or compromised high-privilege accounts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.7, <= 12.2.15CPE matchmatch criteria | cpe:2.3:a:oracle:user_management:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.