Executive brief
Oracle E-Business Suite's HRMS (Human Resource Management System) module for the Netherlands contains a vulnerability in the Payroll component that allows a high-privileged attacker with network access to fully compromise the system. Successful exploitation results in complete takeover of the application, potentially exposing sensitive payroll and employee data, disrupting HR operations, and enabling fraud.
Technical details
This is a privilege escalation or authentication bypass vulnerability in the Oracle HRMS Netherlands Payroll component, requiring high-privilege credentials but no user interaction. The vulnerability is easily exploitable via HTTP network access and allows an attacker to achieve complete system compromise (confidentiality, integrity, and availability impacts). Affected versions are 12.2.3 through 12.2.15 of Oracle E-Business Suite. A patch from Oracle is expected as part of the August 2026 Critical Patch Update.
Affected products
- Oracle E-Business Suite HRMS (Netherlands) 12.2.3-12.2.15
Timeline
- 2026-08-18: disclosed