Junglewise Threat Intelligence

CVE-2026-60900: Oracle HCM Configuration Workbench full compromise in Rapid Implementation

CVE-2026-60900 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle HCM Configuration Workbench. Vendors: Oracle.

Executive brief

A vulnerability exists in the Oracle HCM Configuration Workbench, a tool used within the Oracle E-Business Suite for human resources management and system setup. A high-privileged user can exploit this flaw over the network to gain full control of the workbench component. This could lead to the unauthorized access, modification, or deletion of sensitive HR data and disruption of business operations.

Technical details

This vulnerability affects the Rapid Implementation component of Oracle HCM Configuration Workbench within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires high-privileged credentials to execute. An attacker with network access via HTTP can leverage this vulnerability to achieve a complete takeover of the affected component, impacting confidentiality, integrity, and availability. While the specific CWE is not detailed in the advisory, the impact is described as a full system compromise. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle HCM Configuration Workbench 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD entry published

References

Related threats