Junglewise Threat Intelligence

CVE-2026-62549: Oracle HRMS (UK) data compromise in UK Payroll

CVE-2026-62549 · Severity: critical · CVSS 9.6 · Published 2026-07-21

Technologies: Oracle HRMS (UK). Vendors: Oracle, Oracle Corporation.

Executive brief

A critical vulnerability exists in the UK Payroll component of Oracle HRMS, a system used by organizations to manage human resources and employee compensation. An attacker with basic user access can exploit this flaw over the network to view, modify, or delete sensitive payroll and employee data. Because the vulnerability allows for a 'scope change,' an attack could potentially spread to impact other integrated business systems beyond the HR module.

Technical details

This vulnerability affects the UK Payroll component of Oracle HRMS (UK) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The flaw is notable for a 'scope change' (Status: Changed in CVSS), meaning a successful exploit can impact components or products beyond the immediate UK Payroll module. Attackers can achieve full confidentiality and integrity compromise, allowing for the unauthorized creation, deletion, or modification of all data accessible to the HRMS (UK) product. A patch is expected to be available through the Oracle Critical Patch Update (CPU) program.

Affected products

  • Oracle Corporation HRMS (UK) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle Corporation
  • 2026-07-21: advisory: NVD publication of CVE-2026-62549

References

Related threats