Junglewise Threat Intelligence

CVE-2026-83491: Oracle iRecruitment physical network access vulnerability

CVE-2026-83491 · Severity: medium · CVSS 6.8 · Published 2026-09-15

Technologies: Oracle iRecruitment. Vendors: Oracle.

Executive brief

Oracle iRecruitment is a recruitment and applicant tracking system within Oracle E-Business Suite used by large enterprises to manage hiring. This vulnerability allows an attacker with physical access to the network segment where the system operates to bypass authentication and read, modify, or delete recruitment data without authorization. While the attack requires physical network access (a less common threat), successful exploitation could expose sensitive candidate information and disrupt hiring operations.

Technical details

This is a difficult-to-exploit vulnerability in Oracle iRecruitment (versions 12.2.3 through 12.2.15) accessible to unauthenticated attackers with physical access to the adjacent network segment. The vulnerability allows unauthorized read and write access to critical data stored in iRecruitment. Attack vector requires the attacker to be on the same physical communication segment (network) as the affected system, with no authentication or user interaction required once network access is obtained. Successful exploitation results in confidentiality and integrity compromise of recruitment data. Patch availability from Oracle is assumed but not confirmed in the provided advisory.

Affected products

  • Oracle iRecruitment 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats