Summary
CVE-2026-60780 is a high-severity vulnerability in the Internal Operations component of Oracle Workflow, a core component of Oracle E-Business Suite (EBS), disclosed as part of Oracle’s July 2026 Critical Patch Update. An unauthenticated remote attacker with network access via SMTP can exploit this flaw to fully compromise Oracle Workflow, with no authentication or user interaction required. Successful exploitation results in complete impact to confidentiality, integrity, and availability of the affected system.
Technical details
- Affected component: Internal Operations within Oracle Workflow (Oracle E-Business Suite)
- Attack vector: Network-reachable via SMTP; no privileges or user interaction required (PR:N, UI:N)
- Attack complexity: High (AC:H) — Oracle classifies this as "difficult to exploit," meaning specific conditions must be present; however, this is not a disqualifying factor for organizations with internet-exposed EBS deployments
- Impact: Successful exploitation can result in full takeover of Oracle Workflow, with high impact to confidentiality, integrity, and availability (C:H/I:H/A:H)
- Exposure context: Approximately 950 Oracle E-Business Suite instances have been identified as internet-facing, making network-reachable SMTP-based attacks a realistic threat vector for organizations that have not restricted external access
Affected software
- Oracle Workflow (Oracle E-Business Suite), versions 12.2.3 through 12.2.15
Severity
- CVSS v3.1 Base Score: 8.1 (HIGH)
- Vector:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate: Apply the Oracle July 2026 Critical Patch Update. Oracle E-Business Suite customers should follow the Oracle EBS Release 12 Critical Patch Update Knowledge Document (My Oracle Support Note KA923) for environment-specific patch instructions.
- Network mitigation: Where immediate patching is not feasible, restrict SMTP access to the Oracle Workflow Internal Operations component to trusted internal network segments only and block unauthenticated inbound SMTP from external networks.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

