CVE-2026-34302 is a vulnerability in the Oracle Workflow Loader component of Oracle E-Business Suite affecting versions 12.2.3 through 12.2.15. The flaw allows attackers to compromise the Workflow product and potentially impact other connected E-Business Suite components due to its scope change characteristics. The vulnerability presents a medium severity risk (CVSS 5.5) and requires high privilege access with network connectivity via HTTP to exploit. The attack vector is relatively straightforward with low complexity, requiring no user interaction. Successful exploitation can result in unauthorized data modification or deletion within Oracle Workflow and partial denial of service conditions. Exploitation activity is currently minimal, with the vulnerability absent from public exploit databases and CISA's Known Exploited Vulnerabilities catalog. The EPSS score of 0.00033 indicates exceptionally low probability of exploitation in the wild compared to other disclosed vulnerabilities. Community attention remains limited, suggesting this represents a lower-priority threat requiring standard patch management rather than emergency response protocols.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.2.3, <= 12.2.15CPE matchmatch criteria | cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.