Executive brief
A vulnerability exists in Oracle iRecruitment, a module within the Oracle E-Business Suite used for managing hiring and recruitment processes. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain recruitment data. This could lead to unauthorized access to sensitive candidate information or the corruption of recruitment records.
Technical details
A vulnerability in the 'Install / Upgrade Issues' component of Oracle iRecruitment (part of Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read a subset of iRecruitment data and perform unauthorized updates, insertions, or deletions of accessible records. The affected versions range from 12.2.3 through 12.2.15. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle iRecruitment 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory