Junglewise Threat Intelligence

CVE-2026-62559: Oracle HRMS (US) unauthorized data access in Internal Operations

CVE-2026-62559 · Severity: medium · CVSS 6.8 · Published 2026-07-21

Technologies: Oracle HRMS (US). Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle HRMS (US), a human resources management system within the Oracle E-Business Suite. A high-privileged user could exploit this flaw to gain unauthorized access to sensitive employee data or other critical information across the system. This could lead to a significant breach of confidential corporate and personnel records.

Technical details

A vulnerability in the Internal Operations component of Oracle HRMS (US) (part of Oracle E-Business Suite) allows for unauthorized data access. The flaw is categorized as easily exploitable by a high-privileged attacker with network access via HTTP. While the root cause is within the HRMS module, the vulnerability includes a 'scope change' (S:C), meaning an exploit could impact other components or products within the E-Business Suite environment. Successful exploitation results in a total loss of confidentiality for all data accessible to the HRMS (US) module. Affected versions include 12.2.3 through 12.2.15.

Affected products

  • Oracle HRMS (US) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed: Initial publication of CVE-2026-62559
  • 2026-07-21: advisory: Oracle Critical Patch Update (CPU) July 2026 released

References

Related threats