Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-34302

20
FAUCET Score

CVE-2026-34302 is a vulnerability in the Oracle Workflow Loader component of Oracle E-Business Suite affecting versions 12.2.3 through 12.2.15. The flaw allows attackers to compromise the Workflow product and potentially impact other connected E-Business Suite components due to its scope change characteristics. The vulnerability presents a medium severity risk (CVSS 5.5) and requires high privilege access with network connectivity via HTTP to exploit. The attack vector is relatively straightforward with low complexity, requiring no user interaction. Successful exploitation can result in unauthorized data modification or deletion within Oracle Workflow and partial denial of service conditions. Exploitation activity is currently minimal, with the vulnerability absent from public exploit databases and CISA's Known Exploited Vulnerabilities catalog. The EPSS score of 0.00033 indicates exceptionally low probability of exploitation in the wild compared to other disclosed vulnerabilities. Community attention remains limited, suggesting this represents a lower-priority threat requiring standard patch management rather than emergency response protocols.

Impacted Technologies

VendorProductVersion(s)CPE
>= 12.2.3, <= 12.2.15CPE matchmatch criteria
cpe:2.3:a:oracle:workflow:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
2.3
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 6th percentile among its peer group of 3,562 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

oraclevendor investigatingvia nvd_reference
View patch

References

oracle.com / security-alerts/cpuapr2026.html
Vendor Advisory