Junglewise Threat Intelligence

CVE-2026-62556: Oracle HRMS (US) information disclosure in Internal Operations

CVE-2026-62556 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle HRMS (US). Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle HRMS (US), a human resources management system within the Oracle E-Business Suite. An attacker with low-level user credentials could exploit this flaw over the network to gain unauthorized access to sensitive employee and corporate data. This could lead to a significant breach of confidential information stored within the HR system.

Technical details

This vulnerability affects the Internal Operations component of Oracle HRMS (US) within Oracle E-Business Suite. It is classified as an information disclosure flaw that is easily exploitable via HTTP. An attacker requires low-privileged authentication to the system but no user interaction to succeed. Successful exploitation allows the attacker to gain unauthorized read access to critical data or complete access to all data accessible by the HRMS (US) component. The vulnerability is addressed in the Oracle Critical Patch Update for July 2026.

Affected products

  • Oracle HRMS (US) 12.2.6-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update.
  • 2026-07-21: disclosed

References

Related threats