Junglewise Threat Intelligence

CVE-2026-60750: Oracle Payroll information disclosure in Internal Operations

CVE-2026-60750 · Severity: high · CVSS 7.7 · Published 2026-07-21

Technologies: Oracle Payroll. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in Oracle Payroll, a component of the Oracle E-Business Suite used by organizations to manage employee compensation and tax filings. A low-privileged user with network access could exploit this flaw to gain unauthorized access to sensitive payroll information. Because this issue involves a 'scope change,' an attacker might also be able to impact other integrated business systems beyond just the payroll module.

Technical details

This vulnerability affects the Internal Operations component of Oracle Payroll within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The exploit results in a 'scope change' (S:C), meaning the impact can extend beyond the Oracle Payroll security scope to other products. The primary impact is a high loss of confidentiality (C:H), potentially granting the attacker access to all data within the affected component. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Oracle Payroll 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this vulnerability.
  • 2026-07-21: disclosed

References

Related threats