Junglewise Threat Intelligence

CVE-2026-61119: Oracle HRMS (UK) data manipulation in UK Payroll

CVE-2026-61119 · Severity: high · CVSS 7.1 · Published 2026-07-21

Technologies: Oracle HRMS (UK). Vendors: Oracle.

Executive brief

A vulnerability exists in the UK Payroll component of Oracle HRMS, which is part of the Oracle E-Business Suite used by organizations to manage human resources and payroll processing. An attacker with basic user access to the network can exploit this flaw to modify, create, or delete sensitive payroll data. This could lead to significant financial inaccuracies, unauthorized changes to employee records, and partial disruption of payroll services.

Technical details

This vulnerability affects the UK Payroll component of Oracle HRMS (UK) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged user credentials and network access via HTTP. An attacker can achieve unauthorized creation, deletion, or modification of critical data accessible to the HRMS (UK) module. Additionally, the exploit can cause a partial denial of service (DoS), impacting the availability of the payroll system. The vulnerability has a CVSS 3.1 base score of 7.1, primarily impacting integrity and availability. Patching information is typically found in Oracle's Critical Patch Update (CPU) advisories.

Affected products

  • Oracle HRMS (UK) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Published by Oracle in the July 2026 Critical Patch Update

References

Related threats