Junglewise Threat Intelligence

CVE-2026-62567: Oracle HRMS (UK) information disclosure in UK Payroll

CVE-2026-62567 · Severity: high · CVSS 7.7 · Published 2026-07-21

Vendors: Oracle Corporation.

Executive brief

A vulnerability exists in the UK Payroll component of Oracle E-Business Suite, a system used by organizations to manage human resources and payroll processing. An attacker with basic user access to the network can exploit this flaw to gain unauthorized access to sensitive payroll and employee data. This could lead to a significant breach of confidential information and potentially impact other integrated business systems.

Technical details

This vulnerability is located in the UK Payroll component of Oracle HRMS (UK) within Oracle E-Business Suite. It is classified as an information disclosure flaw that allows a low-privileged attacker with network access via HTTP to compromise the system. The exploit is characterized by a 'scope change' (S:C), meaning a successful attack can impact resources beyond the security scope of the UK Payroll component itself. The primary impact is on confidentiality, potentially granting full access to all data accessible by the HRMS (UK) module. The vulnerability affects versions 12.2.3 through 12.2.15. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle Corporation Oracle HRMS (UK) 12.2.3-12.2.15

Timeline

  • 2026-07-21: advisory: Initial publication of CVE-2026-62567 by Oracle and NVD.

References