Junglewise Threat Intelligence

CVE-2026-62530: Oracle E-Business Suite data compromise in Oracle HRMS France

CVE-2026-62530 · Severity: high · CVSS 8.1 · Published 2026-07-21

Technologies: Oracle HRMS France. Vendors: Oracle.

Executive brief

A vulnerability exists in the French Human Resources component of Oracle E-Business Suite, a platform used by organizations to manage payroll and personnel data. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete sensitive employee information. This could lead to significant data breaches, unauthorized changes to HR records, and non-compliance with privacy regulations.

Technical details

This vulnerability affects the French HR component of Oracle HRMS within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as an easily exploitable flaw that requires low-privileged authentication and network access via HTTP. An attacker can leverage this vulnerability to achieve unauthorized creation, deletion, or modification of critical data, as well as full read access to all data within the affected module. The vulnerability has a CVSS 3.1 base score of 8.1, reflecting high impacts on confidentiality and integrity with no impact on availability. Users should refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle E-Business Suite (Oracle HRMS France) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication by Oracle and NVD
  • 2026-07-21: advisory: Oracle Critical Patch Update July 2026 released

References

Related threats