Junglewise Threat Intelligence

CVE-2026-46955: Oracle Human Resources takeover via Person component

CVE-2026-46955 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle Human Resources. Vendors: Oracle.

Executive brief

A vulnerability in the Oracle Human Resources component of the E-Business Suite could allow an unauthorized person to take full control of the HR system. This software is used by organizations to manage employee data, payroll, and personnel records. To carry out an attack, a legitimate user must be tricked into performing a specific action, which could lead to the exposure of sensitive employee information or disruption of HR operations.

Technical details

This vulnerability exists in the 'Person' component of Oracle Human Resources within the Oracle E-Business Suite. It is classified as a combination of Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), and Open Redirect issues (CWE-79, CWE-352, CWE-601). An unauthenticated attacker can exploit these flaws over HTTP, though the attack complexity is high and requires a victim (other than the attacker) to perform a specific action, such as clicking a malicious link. A successful exploit can result in a complete takeover of the Oracle Human Resources application, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15.

Affected products

  • Oracle Human Resources (E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats