Executive brief
Oracle iRecruitment is a recruitment management system used by organizations as part of Oracle E-Business Suite. A vulnerability in the Internal Operations component allows an attacker with network access and low-level user credentials to bypass access controls and read sensitive hiring and personnel data. Successful exploitation could expose confidential employee and candidate information across the entire recruitment platform.
Technical details
This is an authorization bypass or information disclosure vulnerability in the Oracle iRecruitment Internal Operations component. The flaw is easily exploitable over the network (HTTP) and requires only low-privileged user authentication—no additional interaction needed. An attacker with valid low-level credentials can bypass authorization checks to access critical data normally restricted to higher-privilege roles. The vulnerability has scope change impact, meaning a compromise of iRecruitment can significantly affect other Oracle E-Business Suite products. Patched versions have been released; affected versions are 12.2.3 through 12.2.15.
Affected products
- Oracle iRecruitment 12.2.3-12.2.15
Timeline
- 2026-09-15: disclosed