Junglewise Threat Intelligence

CVE-2026-61025: Oracle iRecruitment compromise in Internal Operations component

CVE-2026-61025 · Severity: high · CVSS 7.2 · Published 2026-07-21

Technologies: Oracle iRecruitment. Vendors: Oracle.

Executive brief

A vulnerability exists in Oracle iRecruitment, a module within the Oracle E-Business Suite used by organizations to manage hiring and candidate tracking. A high-privileged attacker could exploit this flaw to gain full control over the iRecruitment system. This could lead to the unauthorized access of sensitive recruitment data, disruption of hiring operations, and potential compromise of the broader E-Business Suite environment.

Technical details

A vulnerability in the Internal Operations component of Oracle iRecruitment (part of Oracle E-Business Suite) allows for a complete system compromise. The flaw affects versions 12.2.3 through 12.2.15. An attacker requires high privileges and network access via HTTP to exploit the vulnerability. While the specific CWE is not detailed in the advisory, the impact is rated for full loss of confidentiality, integrity, and availability (takeover). Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle iRecruitment 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD.

References

Related threats