Junglewise Threat Intelligence

CVE-2026-87161: Oracle HRMS (India) unauthorized data access in E-Business Suite

CVE-2026-87161 · Severity: high · CVSS 8.5 · Published 2026-09-15

Technologies: Oracle E-Business Suite HRMS (India). Vendors: Oracle.

Executive brief

Oracle HRMS (India) is a human resources management system component within Oracle E-Business Suite that manages employee and payroll data. A vulnerability allows a low-privileged network attacker to gain unauthorized access to sensitive HR data and modify or delete records, potentially exposing critical employee information and disrupting HR operations across the organization.

Technical details

This vulnerability in Oracle HRMS (India), a component of E-Business Suite, is easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the system. The vulnerability results in scope change, meaning successful exploitation may impact additional connected Oracle products beyond HRMS itself. An authenticated attacker can achieve high-impact confidentiality violations (read access to all HRMS-accessible data) and limited integrity violations (unauthorized update, insert, or delete of some HRMS data). Attack requires low privilege access but no user interaction. Patch availability has not been confirmed in the provided advisory details.

Affected products

  • Oracle E-Business Suite HRMS (India) 12.2.3 through 12.2.15

Timeline

  • 2026-09-15: disclosed

References

Related threats