Junglewise Threat Intelligence

CVE-2026-60965: Oracle E-Business Suite data manipulation in HRMS France

CVE-2026-60965 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle HRMS France. Vendors: Oracle.

Executive brief

A vulnerability exists in the French Human Resources component of Oracle E-Business Suite, a platform used by organizations to manage payroll, personnel records, and regulatory compliance. An attacker with basic user access could exploit this flaw to view, modify, or delete sensitive employee data and critical HR records. This could lead to significant data breaches, payroll fraud, or the loss of essential corporate records.

Technical details

This vulnerability affects the French HR component of Oracle HRMS within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that can be triggered over the network via HTTP. An attacker requires low-level privileges (authenticated user) to execute the exploit. Successful exploitation allows for unauthorized creation, deletion, or modification of all accessible data within the Oracle HRMS (France) module, as well as full read access to sensitive information. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity.

Affected products

  • Oracle E-Business Suite (Oracle HRMS France) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats