Description
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in takeover of Oracle iRecruitment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle iRecruitment contains a weakness that permits a high‑privileged attacker with network access to its HTTP interface to fully take over the application. The flaw can be leveraged to alter data and control recruitment processes, leading to confidentiality, integrity and availability violations.

Affected Systems

The affected product is Oracle iRecruitment, a component of Oracle E‑Business Suite. Versions from 12.2.3 through 12.2.15 are impacted.

Risk and Exploitability

The CVSS rating of 7.2 indicates a moderate‑to‑high severity vulnerability with full impact on confidentiality, integrity and availability. The EPSS score of less than 1% suggests that widespread exploitation is unlikely at present. The attack requires network reach to the HTTP interface and that the attacker is already privileged or has compromised credentials. Even though the vulnerability is not listed in CISA’s KEV catalog, successful exploitation would grant the attacker full control of the application, presenting a significant risk to affected organizations.

Generated by OpenCVE AI on August 4, 2026 at 02:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for CVE‑2026‑61025 as detailed in the Oracle CPU July 2026 advisory
  • Restrict network access to the Oracle iRecruitment HTTP interface to trusted hosts or through a VPN tunnel
  • Configure the application to use HTTPS and enforce secure transport to reduce exposure to network‑based attacks

Generated by OpenCVE AI on August 4, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Compromise in Oracle iRecruitment

Thu, 30 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title High-Privilege HTTP Compromise in Oracle iRecruitment

Mon, 27 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Compromise via HTTP in Oracle iRecruitment
Weaknesses CWE-285
CWE-287

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Remote Compromise via HTTP in Oracle iRecruitment
Weaknesses CWE-285
CWE-287

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in takeover of Oracle iRecruitment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle irecruitment
CPEs cpe:2.3:a:oracle:irecruitment:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle irecruitment
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Irecruitment
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:52:21.928Z

Reserved: 2026-07-08T15:51:55.608Z

Link: CVE-2026-61025

cve-icon Vulnrichment

Updated: 2026-07-24T14:52:14.171Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:33.920

Modified: 2026-08-03T18:15:21.883

Link: CVE-2026-61025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses