Junglewise Threat Intelligence

CVE-2026-46827: Oracle E-Business Suite compromise in Oracle Payroll Self Service Manager

CVE-2026-46827 · Severity: high · CVSS 8.8 · Published 2026-05-28

Technologies: Oracle Payroll. Vendors: Oracle.

Executive brief

A vulnerability exists in the Self Service Manager component of Oracle Payroll, a module within the Oracle E-Business Suite used by organizations to manage employee compensation and tax reporting. An attacker with basic user credentials can exploit this flaw over the network to gain full control over the payroll system. This could lead to the unauthorized disclosure of sensitive employee financial data, disruption of payroll operations, or fraudulent modification of payment records.

Technical details

This vulnerability affects the Self Service Manager component of Oracle Payroll within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw allows an attacker to bypass security controls to achieve a complete takeover of the Oracle Payroll module. Successful exploitation results in high impacts to confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for May 2026 for remediation steps.

Affected products

  • Oracle E-Business Suite (Oracle Payroll) 12.2.3-12.2.15

Timeline

  • 2026-05-28: disclosed
  • 2026-05-28: advisory

References

Related threats