Junglewise Threat Intelligence

CVE-2026-60892: Oracle E-Business Suite takeover in Norway Payroll

CVE-2026-60892 · Severity: medium · CVSS 6.6 · Published 2026-07-21

Technologies: Oracle E-Business Suite. Vendors: Oracle.

Executive brief

A vulnerability exists in the Norway Payroll component of Oracle E-Business Suite, a software suite used by organizations to manage human resources and payroll operations. A successful exploit could allow an attacker to take full control of the Norway Payroll system, potentially leading to the exposure of sensitive employee data or disruption of payroll services. While the impact is high, the attack is difficult to perform and requires the attacker to already possess high-level administrative privileges.

Technical details

A vulnerability in the Oracle HRMS (Norway) product of Oracle E-Business Suite, specifically within the Norway Payroll component, allows for a complete system takeover. The flaw is accessible over the network via HTTP but is classified as difficult to exploit (High Attack Complexity). An attacker must already possess high-level administrative privileges (PR:H) to execute the attack. Successful exploitation results in a total loss of confidentiality, integrity, and availability for the affected component. The vulnerability affects versions 12.2.8 through 12.2.15 and was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle E-Business Suite (Oracle HRMS Norway) 12.2.8 - 12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.

References

Related threats