Junglewise Threat Intelligence

CVE-2026-60924: Oracle Public Sector Payroll compromise in Internal Operations

CVE-2026-60924 · Severity: high · CVSS 8.8 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Public Sector Payroll, a module within the Oracle E-Business Suite used by government organizations to manage employee compensation and tax compliance. An attacker with basic user access to the network can exploit this flaw to gain full control over the payroll system. This could lead to the unauthorized disclosure of sensitive employee data, disruption of payroll operations, and the manipulation of financial records.

Technical details

This vulnerability affects the Internal Operations component of Oracle Public Sector Payroll (versions 12.2.3 through 12.2.15). It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The vulnerability allows an attacker to bypass security controls to achieve a complete compromise of the application, impacting confidentiality, integrity, and availability. While the specific CWE is not provided in the advisory, the impact is described as a full system takeover. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Public Sector Payroll (Oracle E-Business Suite) 12.2.3 - 12.2.15

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-60924 by Oracle

References