Junglewise Threat Intelligence

CVE-2026-46922: Oracle HR Intelligence improper privilege management in Internal Operations

CVE-2026-46922 · Severity: high · CVSS 7.2 · Published 2026-06-17

Technologies: Oracle Hr Intelligence. Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle HR Intelligence, a tool used for human resources data analysis within the Oracle E-Business Suite. A high-privileged attacker could exploit this flaw to gain full control over the HR Intelligence system. This could lead to the unauthorized access, modification, or deletion of sensitive employee and organizational data.

Technical details

This vulnerability in Oracle HR Intelligence (Internal Operations component) is characterized by improper privilege management or access control (CWE-269, CWE-284). It is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation allows for a complete takeover of the Oracle HR Intelligence product, impacting confidentiality, integrity, and availability. The issue affects Oracle E-Business Suite versions 12.2.3 through 12.2.15. Security patches are typically released through Oracle's Critical Patch Update (CPU) program.

Affected products

  • Oracle HR Intelligence 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed: Initial disclosure by Oracle
  • 2026-06-17: advisory: NVD publication date

References

Related threats