Junglewise Threat Intelligence

CVE-2026-71104: Oracle E-Business Suite HRMS Netherlands Payroll privilege escalation

CVE-2026-71104 · Severity: high · CVSS 7.2 · Published 2026-08-18

Technologies: Oracle Human Resources Management System. Vendors: Oracle.

Executive brief

Oracle E-Business Suite's HRMS (Human Resource Management System) module for the Netherlands contains a vulnerability in the Payroll component that allows a high-privileged attacker with network access to fully compromise the system. Successful exploitation results in complete takeover of the application, potentially exposing sensitive payroll and employee data, disrupting HR operations, and enabling fraud.

Technical details

This is a privilege escalation or authentication bypass vulnerability in the Oracle HRMS Netherlands Payroll component, requiring high-privilege credentials but no user interaction. The vulnerability is easily exploitable via HTTP network access and allows an attacker to achieve complete system compromise (confidentiality, integrity, and availability impacts). Affected versions are 12.2.3 through 12.2.15 of Oracle E-Business Suite. A patch from Oracle is expected as part of the August 2026 Critical Patch Update.

Affected products

  • Oracle E-Business Suite HRMS (Netherlands) 12.2.3-12.2.15

Timeline

  • 2026-08-18: disclosed

References

Related threats