Junglewise Threat Intelligence

CVE-2026-46971: Oracle HR Intelligence privilege management vulnerability in Internal Operations

CVE-2026-46971 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Oracle Hr Intelligence. Vendors: Oracle.

Executive brief

Oracle HR Intelligence, a component of the Oracle E-Business Suite used for human resources data analysis and reporting, contains a security vulnerability. A person with low-level access to the corporate network could exploit this flaw to take full control of the HR Intelligence system. This could lead to the unauthorized viewing of sensitive employee data, modification of records, or disruption of HR operations.

Technical details

A vulnerability in the Internal Operations component of Oracle HR Intelligence (part of Oracle E-Business Suite) is classified as Improper Privilege Management (CWE-269). The flaw allows a low-privileged attacker with network access via HTTP to compromise the system. While the attack complexity is rated as high, a successful exploit can result in a complete takeover of the Oracle HR Intelligence instance, impacting confidentiality, integrity, and availability. Affected versions range from 12.2.3 through 12.2.15. Users should refer to the Oracle Critical Patch Update for remediation steps.

Affected products

  • Oracle HR Intelligence 12.2.3-12.2.15

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory

References

Related threats