Summary
CVE-2026-62547 is a high-severity vulnerability in the Workflow Notification Mailer component of Oracle Workflow, a core module of Oracle E-Business Suite. An unauthenticated remote attacker with network access via SMTP can exploit this flaw to fully compromise Oracle Workflow, with potential impact to confidentiality, integrity, and availability. The vulnerability was disclosed as part of Oracle’s July 2026 Critical Patch Update and carries a CVSS 3.1 base score of 8.1 (HIGH).
Technical details
- Affected component: Workflow Notification Mailer within Oracle Workflow (Oracle E-Business Suite)
- Attack vector: Network-accessible via SMTP; no authentication or user interaction is required to trigger the vulnerability
- Attack complexity: High — Oracle classifies this as "difficult to exploit," meaning specific conditions must be met for successful exploitation
- Impact: Successful exploitation results in full takeover of Oracle Workflow, with high impact to confidentiality, integrity, and availability of the affected system
- Public PoC: No public proof-of-concept code has been identified at the time of publication
Affected software
- Oracle Workflow (Oracle E-Business Suite) versions 12.2.3 through 12.2.15
Severity
- CVSS v3.1 Base Score: 8.1 (HIGH)
- Vector String:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Mitigation and recommended actions
- Immediate action: Apply Oracle’s July 2026 Critical Patch Update (CPU), released July 21, 2026. This CPU addresses CVE-2026-62547 and contains 410 security patches for Oracle E-Business Suite. Consult Oracle Support Note KA923 (accessible via My Oracle Support) for the specific patch requirements applicable to your EBS environment.
- Network mitigation: Where immediate patching is not feasible, restrict network access to SMTP interfaces used by the Workflow Notification Mailer to trusted internal hosts only. Internet-facing Oracle EBS instances should be assessed for unnecessary public exposure and firewalled accordingly.
- Prioritization context: The Shadowserver Foundation has confirmed approximately 950 internet-facing Oracle E-Business Suite instances are publicly reachable — underscoring the urgency of applying this patch for any organization with externally accessible EBS deployments.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

