Junglewise Threat Intelligence

CVE-2026-60893: Oracle Payroll information disclosure in Internal Operations

CVE-2026-60893 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle Payroll. Vendors: Oracle, Oracle Corporation.

Executive brief

A security vulnerability exists in Oracle Payroll, a component of the Oracle E-Business Suite used for managing employee compensation and tax filings. An individual with low-level access to the underlying server infrastructure could exploit this flaw to gain unauthorized access to sensitive payroll information. This could lead to a significant breach of confidential employee data and potentially impact other integrated business systems.

Technical details

This vulnerability resides in the Internal Operations component of Oracle Payroll within Oracle E-Business Suite. It is classified as a confidentiality-impacting flaw that allows a low-privileged attacker with local logon access to the infrastructure to compromise the application. The exploit is characterized by a 'scope change' (S:C), meaning that a successful attack on Oracle Payroll can facilitate unauthorized access to data or resources in other products within the suite. The attack vector is local, requiring no user interaction and having low complexity. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Oracle Payroll 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed: CVE record published to the NVD.

References

Related threats