Junglewise Threat Intelligence

CVE-2026-61121: Oracle HRMS (UK) system takeover in UK Payroll component

CVE-2026-61121 · Severity: high · CVSS 8.8 · Published 2026-07-21

Technologies: Oracle HRMS (UK). Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the UK Payroll component of Oracle HRMS, a system used by organizations to manage human resources and payroll processing. An attacker with basic user access to the corporate network could exploit this flaw to take full control of the HRMS system. This could lead to the unauthorized disclosure of sensitive employee data, disruption of payroll operations, and loss of data integrity.

Technical details

A vulnerability in the UK Payroll component of Oracle HRMS (UK) (part of Oracle E-Business Suite) allows for a complete system takeover. The flaw is present in versions 12.2.8 through 12.2.15. An attacker requires low-level privileges and network access via HTTP to exploit the vulnerability. Successful exploitation results in high impacts to confidentiality, integrity, and availability. While the specific CWE is not detailed in the advisory, the CVSS vector indicates a straightforward attack path (AC:L) without requiring user interaction. Users should refer to the Oracle July 2026 Critical Patch Update for remediation instructions.

Affected products

  • Oracle Corporation HRMS (UK) 12.2.8-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.

References

Related threats