Junglewise Threat Intelligence

CVE-2026-61080: Oracle E-Business Suite data manipulation in Public Sector Human Resources

CVE-2026-61080 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the Regression Testing component of Oracle Public Sector Human Resources, a module within the Oracle E-Business Suite used for managing government workforce data. An authorized user with low-level permissions could exploit this flaw over the network to view, modify, or delete certain HR records. This could lead to unauthorized changes to employee data or the exposure of sensitive personnel information.

Technical details

A vulnerability in the Regression Testing component of Oracle Public Sector Human Resources (Oracle E-Business Suite) allows for unauthorized data access and modification. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables the attacker to read, insert, update, or delete a subset of data accessible to the module. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Public Sector Human Resources (E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References

Related threats