Junglewise Threat Intelligence

CVE-2026-61142: Oracle Payroll information disclosure in Internal Operations

CVE-2026-61142 · Severity: high · CVSS 7.7 · Published 2026-07-21

Technologies: Oracle Payroll. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle Payroll, a module within the Oracle E-Business Suite used for managing employee compensation and tax compliance. An attacker with basic user credentials can exploit this flaw over the network to gain unauthorized access to sensitive payroll information. This could lead to a significant breach of confidential employee data and potentially impact other integrated business systems.

Technical details

This vulnerability affects the Internal Operations component of Oracle Payroll within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an information disclosure flaw that is easily exploitable by a low-privileged attacker via the HTTP protocol. The exploit results in a scope change (S:C), meaning the impact can extend beyond the Oracle Payroll component to other parts of the E-Business Suite environment. Successful exploitation grants the attacker unauthorized access to critical data or complete access to all data managed by the Oracle Payroll module. The vulnerability was addressed in the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle Corporation Oracle Payroll 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Published as part of the Oracle July 2026 Critical Patch Update
  • 2026-07-21: disclosed

References

Related threats