Executive brief
A vulnerability exists in the UK Payroll component of Oracle HRMS, a module within the Oracle E-Business Suite used for managing human resources and payroll operations. A high-privileged attacker could exploit this flaw to gain full control over the HRMS system. This could lead to the unauthorized access of sensitive employee data, disruption of payroll services, and total compromise of the application's integrity.
Technical details
This vulnerability is classified as Improper Privilege Management (CWE-269) within the UK Payroll component of Oracle HRMS (UK). It is easily exploitable by a high-privileged attacker who has network access via HTTP. The flaw does not require user interaction and has a low attack complexity. Successful exploitation allows an attacker to compromise the Confidentiality, Integrity, and Availability of the system, potentially leading to a complete takeover of the Oracle HRMS (UK) environment. Oracle has addressed this in their June 2026 security update.
Affected products
- Oracle HRMS (UK) 12.2.3-12.2.15
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle Critical Patch Update published