Description
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payroll accessible data as well as unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
Published: 2026-05-28
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Internal Operations component of Oracle Payroll permits an attacker with low-level network access via HTTP to forge requests that create, delete, or alter payroll data. Based on the description, it is inferred that the vulnerability stems from insufficient verification of user privileges, enabling a low-privilege attacker to impact confidentiality and integrity of all payroll records.

Affected Systems

Oracle Corporation’s Oracle Payroll product is affected for all supported releases from 12.2.3 through 12.2.15. The issue can be reached over HTTP by anyone who can connect to the affected server and does not require elevated local or system privileges.

Risk and Exploitability

The CVSS 3.1 base score of 8.1 classifies this vulnerability as high severity. Based on the description, it is inferred that the attacker only needs network connectivity and the ability to assume a low‑privilege role, implying a significant risk of successful compromise. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can use the HTTP interface to send crafted requests that bypass normal authorization checks and affect all payroll data accessible through Payroll.

Generated by OpenCVE AI on May 28, 2026 at 21:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch that addresses the improper access control flaw in Oracle Payroll for versions 12.2.3–12.2.15
  • Limit HTTP access to the Payroll service to only authorized, privileged users or networks, and enforce role‑based access controls
  • Audit and monitor Payroll logs for anomalous or unauthorized write actions, and enforce strict change‑control policies

Generated by OpenCVE AI on May 28, 2026 at 21:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 29 May 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 28 May 2026 22:15:00 +0000

Type Values Removed Values Added
Title Low‑privilege HTTP Attack Enables Modification of Oracle Payroll Data
Weaknesses CWE-284

Thu, 28 May 2026 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Payroll accessible data as well as unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle payroll
CPEs cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payroll
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-05-29T15:35:03.937Z

Reserved: 2026-05-18T15:55:10.304Z

Link: CVE-2026-46828

cve-icon Vulnrichment

Updated: 2026-05-29T15:34:55.703Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-05-28T21:16:32.820

Modified: 2026-05-29T16:16:30.043

Link: CVE-2026-46828

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-29T00:00:11Z

Weaknesses