Vulnerability in Oracle E-Business Suite's HRMS Product
CVE-2026-62548

7.2HIGH

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62548?

A vulnerability exists in Oracle E-Business Suite's HRMS product, specifically in its Internal Operations component. This weakness could allow an attacker with high privileges and network access to leverage HTTP connectivity to gain unauthorized control over the affected systems. When exploited, this vulnerability poses severe risks to the confidentiality, integrity, and availability of the Oracle HRMS (US) implementation, potentially enabling data breaches and system takeovers.

Affected Version(s)

Oracle HRMS (US) 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.