Executive brief
A vulnerability exists in the Oracle Payroll component of the Oracle E-Business Suite, which is used by organizations to manage employee compensation and tax reporting. An attacker with basic user credentials could exploit this flaw over the network to gain unauthorized access to sensitive payroll information. This could lead to the exposure of confidential employee data, including salary details and personal identifiers, potentially resulting in privacy breaches and regulatory non-compliance.
Technical details
This vulnerability affects the Payroll component of Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an information disclosure vulnerability that is easily exploitable by a low-privileged attacker with network access via HTTP. The exploit does not require user interaction and has a high impact on confidentiality, potentially allowing an attacker to access all data within the Oracle Payroll module. The vulnerability was addressed in the Oracle Critical Patch Update for July 2026. While the specific CWE is not provided in the advisory, the attack vector and impact suggest improper access control or an insecure direct object reference within the web interface.
Affected products
- Oracle Corporation Payroll 12.2.3-12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle Critical Patch Update (CPU) published