Unauthorized Access Vulnerability in Oracle HRMS by Oracle
CVE-2026-62521

7.5HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62521?

An exploitable vulnerability exists in the Oracle HRMS (US) component of the Oracle E-Business Suite, specifically in the US Payroll feature. This vulnerability allows unauthenticated attackers with network access via HTTP to gain unauthorized access to sensitive information. If successfully exploited, it can lead to unauthorized disclosures of critical data or full access to all data accessible within the Oracle HRMS (US). This highlights a significant security risk for organizations using this version of the software, making it essential for users to implement appropriate security measures or patches.

Affected Version(s)

Oracle HRMS (US) 12.2.7 <= 12.2.15

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.