Executive brief
Oracle iRecruitment is a recruitment and staffing management component within Oracle E-Business Suite used by enterprises to manage hiring workflows and employee data. This vulnerability allows a low-privileged attacker with network access to bypass access controls and read sensitive hiring and employee information, or modify recruitment records. The flaw affects versions 12.2.3 through 12.2.15 and could also impact other connected modules in the broader E-Business Suite system.
Technical details
This is an authorization bypass or privilege escalation vulnerability in the iRecruitment component (Internal Operations module) of Oracle E-Business Suite. The flaw is easily exploitable via HTTP network requests and requires only low-level privileges (low PR:L) and no user interaction. An authenticated attacker can gain unauthorized read access to critical recruitment and personnel data (High Confidentiality impact) and perform unauthorized modifications to iRecruitment records (Low Integrity impact). The scope is marked as changed, indicating exploitation may affect other Oracle E-Business Suite modules beyond iRecruitment itself. Patches are expected to be available through Oracle's official security updates.
Affected products
- Oracle E-Business Suite iRecruitment 12.2.3 through 12.2.15
Timeline
- 2026-09-15: disclosed