Executive brief
A vulnerability exists in the Oracle Human Resources component of the Oracle E-Business Suite. This software is used by organizations to manage employee data, payroll, and personnel records. An attacker with existing low-level access to the server where the software is installed could exploit this flaw to gain full access to sensitive HR data, allowing them to view, modify, or delete critical employee information.
Technical details
This vulnerability affects the Enterprise Command Center component of Oracle Human Resources within Oracle E-Business Suite versions 12.2.14 and 12.2.15. It is classified as a local exploit, requiring the attacker to have existing logon credentials to the underlying infrastructure where the application executes. The flaw is described as easily exploitable and allows a low-privileged user to achieve high confidentiality and integrity impacts. Successful exploitation enables the attacker to create, delete, or modify all data accessible to the Oracle Human Resources application. The vulnerability was disclosed as part of the Oracle July 2026 Critical Patch Update.
Affected products
- Oracle Human Resources (Enterprise Command Center) 12.2.14, 12.2.15
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory