Junglewise Threat Intelligence

CVE-2026-60966: Oracle Public Sector Human Resources data compromise in Regression Testing

CVE-2026-60966 · Severity: high · CVSS 8.1 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A security vulnerability has been identified in the Regression Testing component of Oracle Public Sector Human Resources, a module within the Oracle E-Business Suite used for managing government and public sector personnel data. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive employee information. Successful exploitation could allow an attacker to view, modify, or delete critical HR records, potentially leading to data breaches or significant operational disruption.

Technical details

This vulnerability exists in the Regression Testing component of Oracle Public Sector Human Resources (versions 12.2.3 through 12.2.15). It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw allows an attacker to bypass intended access controls to achieve high-impact confidentiality and integrity violations. Specifically, an attacker can perform unauthorized creation, deletion, or modification of all accessible data within the module. The vulnerability does not impact system availability but provides complete access to sensitive HR data stores. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle Public Sector Human Resources (E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle in the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats