Executive brief
A vulnerability exists in Oracle iRecruitment, a component of the Oracle E-Business Suite used by organizations to manage hiring and recruitment processes. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive recruitment data. This could lead to the exposure of private applicant information or the unauthorized alteration of critical business records.
Technical details
A vulnerability in the Internal Operations component of Oracle iRecruitment (part of Oracle E-Business Suite) affects versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to perform unauthorized creation, deletion, or modification of critical data, as well as gain full read access to all data accessible via the iRecruitment module. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity, though it does not directly impact service availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation iRecruitment 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.