Executive brief
A vulnerability exists in the French HR Payroll component of Oracle E-Business Suite, which is used by organizations to manage employee compensation and tax compliance in France. An authorized user with low-level access could potentially view, modify, or delete sensitive payroll data they are not supposed to see. This could lead to unauthorized changes in financial records or the exposure of private employee information.
Technical details
This vulnerability affects the French HR Payroll component within Oracle HRMS (France), a part of the Oracle E-Business Suite. It is classified as an improper access control or data validation issue that allows a low-privileged attacker with network access via HTTP to compromise the system. An attacker can successfully perform unauthorized update, insert, or delete operations on a subset of accessible data, as well as gain unauthorized read access to sensitive information. The exploit does not require user interaction and has a low attack complexity. The issue was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle E-Business Suite (Oracle HRMS France) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory