Junglewise Threat Intelligence

CVE-2026-62528: Oracle HCM Configuration Workbench unauthorized data access in Install component

CVE-2026-62528 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle HCM Configuration Workbench, Oracle E-Business Suite. Vendors: Oracle.

Executive brief

A vulnerability exists in the Install component of Oracle HCM Configuration Workbench, a tool used for managing Human Capital Management setups within the Oracle E-Business Suite. An attacker with low-level user credentials could remotely access the system to view, modify, or delete sensitive configuration data. Additionally, this flaw could be used to disrupt the availability of the workbench, potentially impacting administrative operations.

Technical details

This vulnerability affects the Install component of Oracle HCM Configuration Workbench within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. A successful exploit allows an attacker to perform unauthorized CRUD (Create, Read, Update, Delete) operations on a subset of the workbench's data and can lead to a partial denial of service (DoS). The vulnerability has been addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle HCM Configuration Workbench (Oracle E-Business Suite) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed

References

Related threats