Description
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Published: 2026-07-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from an improper access control mechanism in Oracle Payroll’s Internal Operations component. It allows an attacker with only low‑privileged local logon to the host where Oracle Payroll runs to obtain read access to all payroll data. The weakness is classified as CWE‑284. Because the scope is changed, exploitation may also affect other modules within Oracle E‑Business Suite.

Affected Systems

Affected are the Oracle Payroll product in Oracle E‑Business Suite, specifically versions 12.2.3 through 12.2.15. The vulnerability resides in the Internal Operations component of the payroll module.

Risk and Exploitability

The CVSS base score is 6.5 with a local attack vector, low access complexity, low privileges, no user interaction, but a scope change. The EPSS score of <1% indicates that the likelihood of exploitation is low, and the vulnerability is not yet listed in CISA’s KEV. However, the potential impact on confidential payroll data, combined with the requirement of only local access, makes this vulnerability a moderate to high risk for organizations with incomplete isolation of payroll servers.

Generated by OpenCVE AI on August 4, 2026 at 02:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle payroll security patch released in the July 2026 CPU as referenced in the Oracle advisory.
  • Restrict local accounts on payroll servers to the minimum privileges required for operation and enforce strong authentication controls.
  • Audit and monitor for unauthorized local login attempts and consider segmenting payroll servers from the rest of the infrastructure to reduce exposure.

Generated by OpenCVE AI on August 4, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Improper Access Control in Oracle Payroll
Weaknesses CWE-284

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Access via Improper Access Control in Oracle Payroll

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Payroll Leading to Full Data Compromise
Weaknesses CWE-284

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Payroll Leading to Full Data Compromise
Weaknesses CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Payroll executes to compromise Oracle Payroll. While the vulnerability is in Oracle Payroll, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Payroll accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
First Time appeared Oracle
Oracle payroll
CPEs cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payroll
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:31:14.677Z

Reserved: 2026-07-08T15:51:55.599Z

Link: CVE-2026-60893

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses