Junglewise Threat Intelligence

CVE-2026-61122: Oracle HRMS (UK) data compromise in UK Payroll

CVE-2026-61122 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle HRMS (UK). Vendors: Oracle.

Executive brief

A vulnerability exists in the UK Payroll component of Oracle HRMS, which is part of the Oracle E-Business Suite used by organizations to manage human resources and payroll processing. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive payroll and employee data. This could lead to the theft of personal information or the unauthorized modification and deletion of critical financial records.

Technical details

This vulnerability affects the UK Payroll component of Oracle HRMS (UK) within Oracle E-Business Suite versions 12.2.9 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and can be executed over the network via HTTP. Successful exploitation allows an attacker to achieve high confidentiality and integrity impacts, including full access to or modification of all data accessible by the HRMS (UK) module. The vulnerability does not impact system availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation details.

Affected products

  • Oracle HRMS (UK) 12.2.9-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats