Executive brief
A vulnerability exists in the Oracle US Federal Human Resources component of the Oracle E-Business Suite, which is used by government agencies to manage personnel data. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive HR records. This could lead to significant data breaches or the unauthorized alteration of critical government personnel information.
Technical details
This vulnerability affects the Internal Operations component of Oracle US Federal Human Resources within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve unauthorized creation, deletion, or modification of critical data, as well as complete read access to all data accessible by the module. The vulnerability does not impact availability (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.
Affected products
- Oracle E-Business Suite (Oracle US Federal Human Resources) 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-60982
- 2026-07-21: advisory: Oracle released security alert as part of the July 2026 CPU