Junglewise Threat Intelligence

CVE-2026-46954: Oracle Human Resources takeover in Data Removal Tool

CVE-2026-46954 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle Human Resources. Vendors: Oracle.

Executive brief

A vulnerability exists in the Data Removal Tool component of Oracle Human Resources, a module within the Oracle E-Business Suite used for managing employee data and compliance. A high-privileged attacker could exploit this flaw to gain full control over the Human Resources system. This could lead to the unauthorized access, modification, or deletion of sensitive personnel records and organizational data.

Technical details

A vulnerability in the Data Removal Tool component of Oracle Human Resources (part of Oracle E-Business Suite) allows for a complete system takeover. The flaw is easily exploitable by a high-privileged attacker with network access via HTTP. Successful exploitation results in a total loss of confidentiality, integrity, and availability for the affected component. The vulnerability affects versions 12.2.3 through 12.2.15 and was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Human Resources (E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this CVE.
  • 2026-07-21: disclosed

References

Related threats