Executive brief
A vulnerability exists in the UK Payroll component of Oracle HRMS, a module within the Oracle E-Business Suite used for managing human resources and payroll operations. An attacker with basic user credentials could exploit this flaw over the network to view, modify, or delete sensitive payroll data. This could lead to unauthorized changes in employee records or the exposure of private financial information.
Technical details
This vulnerability affects the UK Payroll component of Oracle HRMS (UK) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged user authentication. An attacker can exploit this via the network using HTTP to gain unauthorized read, update, insert, or delete access to a subset of data within the HRMS module. The vulnerability has a CVSS 3.1 base score of 5.4, impacting both confidentiality and integrity. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.
Affected products
- Oracle Corporation Oracle HRMS (UK) 12.2.3-12.2.15
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 Critical Patch Update.
- 2026-07-21: disclosed: CVE-2026-61260 was published to the NVD.