Executive brief
A vulnerability exists in the Affordable Care Act component of Oracle Advanced Benefits, a tool used by organizations to manage employee benefits and regulatory compliance. An attacker with basic user access could exploit this flaw to gain full control over the benefits system. This could lead to the unauthorized disclosure of sensitive employee data, disruption of benefits administration, and loss of data integrity.
Technical details
This vulnerability affects the Affordable Care Act component within Oracle Advanced Benefits (part of Oracle E-Business Suite). It is classified as difficult to exploit (High Attack Complexity), requiring a low-privileged attacker to have network access via HTTP. A successful exploit allows for a complete compromise of the component, impacting confidentiality, integrity, and availability (C:H/I:H/A:H). The vulnerability affects versions 12.2.7 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle Advanced Benefits 12.2.7-12.2.15
Timeline
- 2026-07-21: advisory: Published by Oracle and NVD