Oracle disclosed a critical (CVSS 9.9) vulnerability in the Human Workflow component of Oracle Business Process Management Suite that lets a low-privileged, network-based attacker fully compromise the product.
What Is It
CVE-2026-60542 is a critical vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware, specifically the Human Workflow component. According to Oracle's advisory, the flaw is easily exploitable and allows a low-privileged attacker with network access via the T3 or IIOP protocols to compromise the suite. Successful attacks can result in a complete takeover of Oracle Business Process Management Suite.
Why It Matters
The vulnerability carries a CVSS 3.1 base score of 9.9 (CRITICAL), with high impacts to confidentiality, integrity, and availability. The attack vector is network-based with low attack complexity and requires no user interaction. Critically, the CVSS scope is "Changed"; while the vulnerability resides in Oracle Business Process Management Suite, Oracle notes that attacks may significantly impact additional products beyond the vulnerable component. Because only low privileges are required and exploitation is described as easy, the barrier to abuse is minimal.
What's Vulnerable
Per the NVD record, the affected supported versions are:
- Oracle Business Process Management Suite 12.2.1.4.0
- Oracle Business Process Management Suite 14.1.2.0.0
Exploitation occurs over the T3 and IIOP protocols with network access.
Patch Status
Oracle addressed this vulnerability in its July 2026 Critical Patch Update. Organizations running the affected versions should apply the fixes referenced in Oracle's Critical Patch Update advisory. No CISA KEV entry was supplied for this CVE, so active exploitation is not confirmed in the provided source material.
Sources
- Oracle Critical Patch Update Advisory (July 2026), https://www.oracle.com/security-alerts/cpujul2026.html
- NVD, CVE-2026-60542, https://nvd.nist.gov/vuln/detail/CVE-2026-60542