Vulnerability in Oracle E-Business Suite UK Payroll Product
CVE-2026-62549

9.6CRITICAL

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-62549?

The vulnerability in the Oracle HRMS (UK) product of the Oracle E-Business Suite permits low-privileged attackers with network access to compromise the system. By exploiting this vulnerability, attackers can potentially create, delete, or modify critical data. Given its nature, the scope of impact extends beyond the Oracle HRMS (UK) to other products within the E-Business Suite framework. This situation poses significant risks, including unauthorized access to sensitive data and complete data compromise.

Affected Version(s)

Oracle HRMS (UK) 12.2.3 <= 12.2.15

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.