Junglewise Threat Intelligence

CVE-2026-62456: Oracle HRMS (UK) unauthorized data access in Internal Operations

CVE-2026-62456 · Severity: high · CVSS 8.2 · Published 2026-07-21

Technologies: Oracle HRMS (UK). Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle HRMS (UK), a human resources management system within the Oracle E-Business Suite. A low-privileged user could exploit this flaw to gain unauthorized access to sensitive personnel data or modify critical business records. Because this issue can impact other connected systems, a successful attack could lead to a broader compromise of corporate data and operations.

Technical details

This vulnerability affects the Internal Operations component of Oracle HRMS (UK) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as difficult to exploit (High Attack Complexity) and requires the attacker to have low-level privileges and network access via HTTPS. A successful exploit results in a scope change (S:C), meaning the attacker can impact components beyond the immediate HRMS environment. The impact includes unauthorized creation, deletion, or modification of critical data, as well as complete confidentiality loss of all accessible HRMS data. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle HRMS (UK) (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats