Impact
CVE-2026-60925 is a high‑privilege takeover vulnerability that allows an attacker who already possesses high‑privileged network access via HTTP to compromise the Oracle Public Sector Payroll application. The flaw is identified as CWE‑269, CWE‑284, and CWE‑306, and the description states it is easily exploitable. Based on the description, it is inferred that the attacker can bypass authentication controls and achieve full control of the payroll application, resulting in loss of confidentiality, integrity, and availability.
Affected Systems
Affected are Oracle Public Sector Payroll versions 12.2.4 through 12.2.15, part of the Oracle E‑Business Suite's Internal Operations component.
Risk and Exploitability
The CVSS 3.1 base score of 7.2 indicates moderate to high severity. EPSS score of less than 1% suggests a low probability of active exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network access over HTTP and may use the flaw to take complete control of the system. Based on the description, exploitation requires high‑privileged network access.
OpenCVE Enrichment