Junglewise Threat Intelligence

CVE-2026-61216: Oracle Payroll unauthorized data access and partial DoS

CVE-2026-61216 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle Payroll. Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Oracle Payroll component of the Oracle E-Business Suite, which is used by organizations to manage employee compensation and tax filings. An employee or other user with low-level access to the system could potentially view, modify, or delete sensitive payroll data. Additionally, an attacker could disrupt payroll operations, leading to a partial service outage.

Technical details

This vulnerability affects the Payroll component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and is accessible over the network via HTTP. An attacker can exploit this to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of Oracle Payroll data. Furthermore, the exploit can be used to cause a partial denial of service (DoS) affecting the availability of the payroll system. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Payroll 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update published

References

Related threats