Junglewise Threat Intelligence

CVE-2026-60899: Oracle HCM Configuration Workbench information disclosure in Rapid Implementation

CVE-2026-60899 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle HCM Configuration Workbench. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Rapid Implementation component of Oracle HCM Configuration Workbench, a tool used for setting up human resources and payroll systems within the Oracle E-Business Suite. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive organizational data. This could lead to a significant breach of confidential employee or corporate information stored within the HCM system.

Technical details

An information disclosure vulnerability exists in the Rapid Implementation component of Oracle HCM Configuration Workbench (part of Oracle E-Business Suite). The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended confidentiality restrictions, resulting in unauthorized access to critical data or complete access to all data accessible by the HCM Configuration Workbench. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle addressed this in the July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation HCM Configuration Workbench (Oracle E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Oracle released the July 2026 Critical Patch Update containing this fix.
  • 2026-07-21: disclosed

References

Related threats