Junglewise Threat Intelligence

CVE-2026-61255: Oracle HRMS (New Zealand) data manipulation in New Zealand Payroll

CVE-2026-61255 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A vulnerability exists in the New Zealand Payroll component of Oracle HRMS, a system used by organizations to manage employee data and payroll processing. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive payroll information. This could lead to unauthorized changes in financial records or the exposure of private employee data.

Technical details

This vulnerability affects the New Zealand Payroll component of Oracle HRMS (New Zealand) within the Oracle E-Business Suite. It is classified as an easily exploitable flaw that requires low-privileged user authentication and network access via HTTP. An attacker can leverage this vulnerability to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the data accessible to the HRMS application. The vulnerability impacts confidentiality and integrity but does not affect system availability. Affected versions include 12.2.3 through 12.2.15.

Affected products

  • Oracle HRMS (New Zealand) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.

References