Junglewise Threat Intelligence

CVE-2026-61214: Oracle E-Business Suite information disclosure in UK Payroll

CVE-2026-61214 · Severity: low · CVSS 2.2 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the UK Payroll component of Oracle E-Business Suite, a platform used by organizations to manage human resources and payroll operations. An attacker with high-level administrative privileges could potentially gain unauthorized access to a limited amount of sensitive HR data. While the risk is low due to the high level of access required and the difficulty of the exploit, it could lead to minor data exposure within the payroll system.

Technical details

This vulnerability affects the UK Payroll component of Oracle HRMS (UK) within Oracle E-Business Suite. It is classified as a low-severity information disclosure bug that is difficult to exploit (Attack Complexity: High). An attacker requires high-privileged credentials and network access via HTTP to successfully execute the exploit. If successful, the attacker can achieve unauthorized read access to a specific subset of data accessible to the HRMS (UK) module. The vulnerability is addressed in the Oracle Critical Patch Update (CPU) for July 2026.

Affected products

  • Oracle E-Business Suite (Oracle HRMS UK) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed

References