Junglewise Threat Intelligence

CVE-2026-62524: Oracle E-Business Suite HRMS data manipulation in US Payroll

CVE-2026-62524 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle E-Business Suite HRMS (US). Vendors: Oracle.

Executive brief

A vulnerability exists in the US Payroll component of Oracle E-Business Suite, a platform used by organizations to manage human resources and financial operations. An attacker with basic user access to the network could potentially view, modify, or delete sensitive payroll data. Additionally, an exploit could cause partial service disruptions, impacting the organization's ability to process payroll or manage employee records effectively.

Technical details

A vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite, specifically within the US Payroll - General component, allows for unauthorized data manipulation and access. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to perform unauthorized update, insert, or delete operations on a subset of accessible data, as well as gain unauthorized read access. It also allows for the creation of a partial denial-of-service (DoS) condition. The affected versions range from 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle E-Business Suite HRMS (US) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References

Related threats