Junglewise Threat Intelligence

CVE-2026-61260: Oracle HRMS (UK) unauthorized data access in UK Payroll

CVE-2026-61260 · Severity: medium · CVSS 5.4 · Published 2026-07-21

Technologies: Oracle HRMS (UK). Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the UK Payroll component of Oracle HRMS, a module within the Oracle E-Business Suite used for managing human resources and payroll operations. An attacker with basic user credentials could exploit this flaw over the network to view, modify, or delete sensitive payroll data. This could lead to unauthorized changes in employee records or the exposure of private financial information.

Technical details

This vulnerability affects the UK Payroll component of Oracle HRMS (UK) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged user authentication. An attacker can exploit this via the network using HTTP to gain unauthorized read, update, insert, or delete access to a subset of data within the HRMS module. The vulnerability has a CVSS 3.1 base score of 5.4, impacting both confidentiality and integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle HRMS (UK) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed: CVE-2026-61260 was published to the NVD.

References

Related threats