Executive brief
A vulnerability exists in the Oracle Payroll component of the Oracle E-Business Suite, which is used by organizations to manage employee compensation and tax filings. An attacker with low-level access to the corporate network could exploit this flaw to take full control of the payroll system. This could lead to the unauthorized disclosure of sensitive employee financial data, disruption of payroll operations, or fraudulent modification of payment records.
Technical details
This vulnerability affects the Internal Operations component of Oracle Payroll within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires only low-privileged authentication and network reachability via HTTPS. While the specific CWE is not detailed in the advisory, the impact is a complete compromise of Confidentiality, Integrity, and Availability (CIA triad), effectively allowing an attacker to take over the Oracle Payroll instance. Organizations should refer to the Oracle Critical Patch Update for May 2026 for remediation steps.
Affected products
- Oracle E-Business Suite Payroll 12.2.3-12.2.15
Timeline
- 2026-05-28: disclosed: Initial disclosure by Oracle
- 2026-05-28: advisory: NVD record published