Junglewise Threat Intelligence

CVE-2026-87159: Oracle E-Business Suite HRMS (India) unauthorized data access and modification

CVE-2026-87159 · Severity: high · CVSS 8.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite HRMS (India). Vendors: Oracle.

Executive brief

Oracle HRMS (India) is a human resources management system component of Oracle E-Business Suite used by organizations to manage employee data and payroll operations. An authenticated attacker with network access can exploit a vulnerability in this module to read, modify, or delete sensitive employee and HR data without proper authorization, potentially affecting payroll, benefits, and personnel records.

Technical details

This vulnerability in Oracle E-Business Suite's HRMS (India) component allows a low-privileged authenticated attacker with network access via HTTP to bypass authorization controls. The attack requires valid credentials but no user interaction. Successful exploitation enables unauthorized creation, deletion, or modification of critical HR data, as well as unauthorized read access to all accessible data within the HRMS module. The vulnerability is easily exploitable and affects HRMS versions 12.2.3 through 12.2.15. Patch availability and specific technical remediation details are not provided in the advisory summary.

Affected products

  • Oracle E-Business Suite HRMS (India) 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats