Junglewise Threat Intelligence

CVE-2026-62519: Oracle E-Business Suite data manipulation in Succession Planning

CVE-2026-62519 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Vendors: Oracle Corporation, Oracle.

Executive brief

A vulnerability exists in the Succession Planning component of Oracle E-Business Suite, which is used by organizations to manage talent pipelines and leadership transitions. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive succession data. This could lead to the unauthorized disclosure of personnel information or disruptions to HR planning operations.

Technical details

A vulnerability in the Succession Plan component of Oracle E-Business Suite (versions 12.2.3 through 12.2.15) allows for unauthorized data manipulation and disclosure. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read, insert, update, or delete a subset of data within the Succession Planning module, and can also result in a partial denial of service (DoS). The vulnerability was addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle Corporation Succession Planning 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released

References