Executive brief
Oracle E-Business Suite's HRMS (US) product, which manages payroll and human resources operations for enterprise customers, contains a vulnerability that could allow an attacker with high-level system access to gain complete control over the system. Successful exploitation could compromise sensitive employee payroll data, HR records, and disrupt critical payroll processing operations across an organization.
Technical details
This is a privilege escalation vulnerability in the US Payroll - General component of Oracle HRMS within E-Business Suite. The vulnerability is difficult to exploit and requires high privilege level and network access via HTTP; however, it has a scope change, meaning successful exploitation could impact additional products beyond HRMS itself. An attacker with high-level administrative privileges and network access can achieve complete system takeover (confidentiality, integrity, and availability impact). Patches are available from Oracle's Critical Patch Update program (CPUAug2026 or later).
Affected products
- Oracle E-Business Suite HRMS (US) 12.2.3 to 12.2.15
Timeline
- 2026-08-18: disclosed