CVE-2026-22014
Unauthorized Data Modification Vulnerability in Oracle User Management
Publication date: 2026-04-21
Last updated on: 2026-04-23
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | user_management | From 12.2.7 (inc) to 12.2.15 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
This vulnerability allows a high privileged attacker with network access to perform unauthorized read, insert, update, or delete operations on Oracle User Management accessible data. Such unauthorized access and modification of data could potentially lead to non-compliance with data protection regulations like GDPR and HIPAA, which require strict controls over data confidentiality and integrity.
However, the provided information does not explicitly mention the impact on compliance with specific standards or regulations.
Can you explain this vulnerability to me?
This vulnerability exists in the Oracle User Management product of Oracle E-Business Suite, specifically in the Workflow and Business Events component. It affects supported versions 12.2.7 through 12.2.15. The vulnerability is easily exploitable by a high privileged attacker who has network access via HTTP.
A successful attack can allow the attacker to perform unauthorized updates, inserts, or deletions of some data accessible through Oracle User Management, as well as unauthorized read access to a subset of that data.
How can this vulnerability impact me? :
The impact of this vulnerability includes unauthorized modification and disclosure of data within Oracle User Management. An attacker with high privileges and network access could alter or delete data, or read sensitive information without authorization.
This could lead to data integrity issues and confidentiality breaches within the affected Oracle E-Business Suite environment.