Junglewise Threat Intelligence

CVE-2026-87160: Oracle HRMS (India) unauthorized data access in E-Business Suite

CVE-2026-87160 · Severity: high · CVSS 7.1 · Published 2026-09-15

Technologies: Oracle E-Business Suite HRMS (India). Vendors: Oracle.

Executive brief

Oracle HRMS (India) is a human resources management system component within Oracle E-Business Suite that processes employee data and personnel operations. A vulnerability allows low-privileged users with network access to bypass authorization controls, exposing sensitive employee and payroll data or making unauthorized changes to personnel records. This could result in data theft, compliance violations, and disruption to HR operations.

Technical details

The vulnerability in Oracle HRMS (India) is an authorization bypass affecting versions 12.2.3 through 12.2.15. It is easily exploitable via HTTPS by an attacker with low privileges and network access, without requiring user interaction. The flaw resides in the Internal Operations component and allows unauthorized read access to critical HR data and write access (insert, update, delete) to some accessible data. Attackers can exfiltrate sensitive personnel information or corrupt HR records. A patch is expected from Oracle; check Oracle's official security advisories for patched versions.

Affected products

  • Oracle E-Business Suite HRMS (India) 12.2.3-12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats