Junglewise Threat Intelligence

CVE-2026-62562: Oracle HRMS (US) information disclosure in Internal Operations

CVE-2026-62562 · Severity: medium · CVSS 6.5 · Published 2026-07-21

Technologies: Oracle HRMS (US). Vendors: Oracle.

Executive brief

A vulnerability exists in the Internal Operations component of Oracle HRMS (US), a human resources management system within the Oracle E-Business Suite. An employee or user with low-level access to the system could exploit this flaw over the network to view sensitive personnel data they are not authorized to see. This could lead to a significant breach of employee privacy and unauthorized access to critical corporate HR records.

Technical details

An information disclosure vulnerability exists in the Internal Operations component of Oracle HRMS (US) within Oracle E-Business Suite versions 12.2.3 through 12.2.15. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation allows the attacker to bypass intended confidentiality restrictions, resulting in unauthorized access to critical data or complete access to all data accessible by the HRMS (US) module. The vulnerability is tracked as part of the Oracle July 2026 Critical Patch Update.

Affected products

  • Oracle HRMS (US) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Oracle published the July 2026 Critical Patch Update containing this vulnerability.

References

Related threats