Junglewise Threat Intelligence

CVE-2026-60890: Oracle Payroll compromise in Internal Operations component

CVE-2026-60890 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle Payroll. Vendors: Oracle Corporation, Oracle.

Executive brief

Oracle Payroll, a core component of the Oracle E-Business Suite used for managing employee compensation and tax compliance, contains a high-severity security vulnerability. An attacker with basic user access to the corporate network can exploit this flaw to gain full control over the payroll system. This could lead to the unauthorized disclosure of sensitive employee data, disruption of payroll operations, or fraudulent financial activity.

Technical details

This vulnerability exists in the Internal Operations component of Oracle Payroll within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. Successful exploitation can result in a complete takeover of the Oracle Payroll application, impacting confidentiality, integrity, and availability. The vulnerability requires low administrative privileges and no user interaction. Affected versions range from 12.2.3 to 12.2.15, and users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle Payroll (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the security alert as part of the July 2026 CPU.
  • 2026-07-21: disclosed: CVE-2026-60890 was published to the NVD.

References

Related threats