Description
Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HCM Configuration Workbench accessible data as well as unauthorized read access to a subset of Oracle HCM Configuration Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
Published: 2026-07-21
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a weakness in the Spreadsheet Loading component of Oracle HCM Configuration Workbench that allows an unauthenticated attacker with network access via HTTP to modify, insert, or delete data, read sensitive data, and cause a partial denial of service. The flaw is rooted in several weaknesses including missing authentication (CWE‑306), missing authorization (CWE‑862), improper access control (CWE‑284), and information exposure (CWE‑200).

Affected Systems

Oracle HCM Configuration Workbench, part of Oracle E‑Business Suite, is affected in supported versions 12.2.3 through 12.2.15.

Risk and Exploitability

The CVSS base score of 7.3 reflects moderate to high impact on confidentiality, integrity, and availability. The EPSS score is below 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog. Attackers would need no authentication, merely HTTP access to the vulnerable component, making it potentially exploitable from the network, though not explicitly listed as a known exploit.

Generated by OpenCVE AI on August 4, 2026 at 01:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle HCM Configuration Workbench patch that addresses the Spreadsheet Loading vulnerability.
  • Review and enforce role‑based permissions for HCM Configuration Workbench to limit update, delete, and read operations, following Oracle security best practices.
  • If spreadsheet functionality is unnecessary, disable Spreadsheet Loading or block its HTTP endpoint with firewall or web server configuration to restrict access.

Generated by OpenCVE AI on August 4, 2026 at 01:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Data Modification via Spreadsheet Loading in Oracle HCM Configuration Workbench

Thu, 30 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Unauthenticated Spreadsheet Loading Vulnerability Enables Unauthorized Data Modification and Denial of Service

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated Spreadsheet Loading Vulnerability Enables Unauthorized Data Modification and Denial of Service

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-306
CWE-862
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HCM Configuration Workbench product of Oracle E-Business Suite (component: Spreadsheet Loading). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle HCM Configuration Workbench. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle HCM Configuration Workbench accessible data as well as unauthorized read access to a subset of Oracle HCM Configuration Workbench accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle HCM Configuration Workbench. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).
First Time appeared Oracle
Oracle hcm Configuration Workbench
CPEs cpe:2.3:a:oracle:hcm_configuration_workbench:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hcm Configuration Workbench
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

Oracle Hcm Configuration Workbench
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:12:45.113Z

Reserved: 2026-07-08T15:52:20.744Z

Link: CVE-2026-61267

cve-icon Vulnrichment

Updated: 2026-07-22T18:12:41.346Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:15:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function

  • CWE-862

    Missing Authorization