Junglewise Threat Intelligence

CVE-2026-62561: Oracle HRMS (US) compromise in Internal Operations component

CVE-2026-62561 · Severity: high · CVSS 7.8 · Published 2026-07-21

Technologies: Oracle HRMS (US). Vendors: Oracle, Oracle Corporation.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle HRMS (US), a human resources management system within the Oracle E-Business Suite. An attacker with basic access to the underlying server infrastructure could exploit this flaw to take full control of the HRMS application. This could lead to the unauthorized access, modification, or deletion of sensitive employee data and payroll information, potentially disrupting business operations and compromising regulatory compliance.

Technical details

A vulnerability in the Internal Operations component of Oracle HRMS (US) (part of Oracle E-Business Suite) allows for a complete compromise of the application. The flaw is classified as easily exploitable but requires the attacker to have local logon access to the infrastructure where the HRMS software executes. Successful exploitation allows a low-privileged user to achieve a full takeover of the Oracle HRMS (US) instance, impacting confidentiality, integrity, and availability. The affected versions range from 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation HRMS (US) 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Oracle Critical Patch Update (CPU) published

References

Related threats