Unauthenticated Access Risk in Oracle Human Resources by Oracle
CVE-2026-46955

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
16 June 2026

What is CVE-2026-46955?

A security vulnerability in Oracle Human Resources, part of the Oracle E-Business Suite, allows unauthenticated attackers with network access to potentially exploit the system. This risk involves a reliance on human interaction, requiring the involvement of a victim to enable successful attacks. The affected versions range from 12.2.3 to 12.2.15, underscoring the need for Oracle users to apply necessary patches and mitigations to safeguard against potential system takeover.

Affected Version(s)

Oracle Human Resources 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.