Junglewise Threat Intelligence

CVE-2026-61075: Oracle Self-Service Human Resources unauthorized data access in Internal Operations

CVE-2026-61075 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Self-Service Human Resources, a tool used by employees to manage their personal and employment information. An attacker with basic user credentials could exploit this flaw to view, modify, or delete certain HR-related data. This could lead to unauthorized changes to employee records or the exposure of sensitive internal information.

Technical details

A vulnerability in the Internal Operations component of Oracle Self-Service Human Resources (part of Oracle E-Business Suite) allows for unauthorized data access and manipulation. The flaw is exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read, insert, update, or delete a subset of data accessible to the Self-Service Human Resources module. The vulnerability affects versions 12.2.3 through 12.2.15. Oracle addressed this issue in the July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Self-Service Human Resources 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Initial disclosure by Oracle and NVD publication.

References

Related threats