Junglewise Threat Intelligence

CVE-2026-70690: Oracle E-Business Suite HRMS (US) privilege escalation in Payroll

CVE-2026-70690 · Severity: high · CVSS 8 · Published 2026-08-18

Technologies: Oracle Human Resources Management System, Oracle E-Business Suite HRMS (US). Vendors: Oracle.

Executive brief

Oracle E-Business Suite's HRMS (US) product, which manages payroll and human resources operations for enterprise customers, contains a vulnerability that could allow an attacker with high-level system access to gain complete control over the system. Successful exploitation could compromise sensitive employee payroll data, HR records, and disrupt critical payroll processing operations across an organization.

Technical details

This is a privilege escalation vulnerability in the US Payroll - General component of Oracle HRMS within E-Business Suite. The vulnerability is difficult to exploit and requires high privilege level and network access via HTTP; however, it has a scope change, meaning successful exploitation could impact additional products beyond HRMS itself. An attacker with high-level administrative privileges and network access can achieve complete system takeover (confidentiality, integrity, and availability impact). Patches are available from Oracle's Critical Patch Update program (CPUAug2026 or later).

Affected products

  • Oracle E-Business Suite HRMS (US) 12.2.3 to 12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats