Description
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Oracle Payroll component of Oracle E-Business Suite. It allows a low‑privileged attacker with network access over HTTP to compromise the Payroll application, potentially taking full control of the system. The flaw is difficult to exploit but, if successful, results in a complete takeover with all confidentiality, integrity and availability properties compromised. The description and CVSS vector imply that improper access control or authorization checks are the root cause, roughly mapping to CWE-284.

Affected Systems

Affected systems are Oracle Corporation's Oracle Payroll, specifically the Internal Operations component. Supported versions 12.2.3 through 12.2.15 are impacted. No other versions or product variants are listed in the current advisory.

Risk and Exploitability

The CVSS base score of 7.5 designates a high severity vulnerability. The EPSS score indicates a very low exploitation probability (<1%), and the issue is not listed in the CISA KEV catalog. Because the flaw can be triggered by an actor with limited privileges and remote network access, the risk is significant for organizations that expose Oracle Payroll to external networks. While the low EPSS suggests that widespread exploitation is unlikely at present, the potential for a complete takeover warrants prompt remediation.

Generated by OpenCVE AI on August 4, 2026 at 02:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Payroll security patch provided by Oracle
  • Restrict HTTP access to Oracle Payroll to privileged users or isolate the service within a secure network segment
  • Enable detailed logging for Payroll access and monitor for anomalous activity to detect attempted exploitation

Generated by OpenCVE AI on August 4, 2026 at 02:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title Remote Exploitation Enables Low‑Privilege Takeover of Oracle Payroll

Tue, 28 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Network Attack Can Compromise Oracle Payroll
Weaknesses CWE-285

Sat, 25 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Low‑Privileged Network Attack Can Compromise Oracle Payroll
Weaknesses CWE-284
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle payroll
CPEs cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payroll
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T17:30:01.200Z

Reserved: 2026-07-08T15:51:55.599Z

Link: CVE-2026-60894

cve-icon Vulnrichment

Updated: 2026-07-24T17:29:54.720Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:30:02Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function