Junglewise Threat Intelligence

CVE-2026-46828: Oracle E-Business Suite data compromise in Oracle Payroll

CVE-2026-46828 · Severity: high · CVSS 8.1 · Published 2026-05-28

Technologies: Oracle Payroll. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Payroll, a module within the Oracle E-Business Suite used for managing employee compensation and tax compliance. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive payroll data. This could lead to significant financial data inaccuracies, unauthorized salary changes, or the exposure of confidential employee information.

Technical details

This vulnerability affects the Internal Operations component of Oracle Payroll within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve unauthorized creation, deletion, or modification of critical payroll data, as well as gain complete read access to all data accessible by the Oracle Payroll module. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability.

Affected products

  • Oracle E-Business Suite (Oracle Payroll) 12.2.3-12.2.15

Timeline

  • 2026-05-28: disclosed: Initial disclosure by Oracle
  • 2026-05-28: advisory: NVD publication date

References

Related threats