Description
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Oracle Payroll versions 12.2.3 through 12.2.15 contain a flaw in internal operations that allows an attacker with a low‑privilege account and network access via HTTP to compromise the application. The weakness permits the attacker to bypass standard privilege limits (CWE‑269), improper access control (CWE‑284), improper authentication (CWE‑287), and missing authentication for critical functions (CWE‑306). As a result, the attacker can gain full control over payroll processing, access confidential employee information, alter payroll data, and potentially disrupt service availability.

Affected Systems

Oracle Corporation’s Oracle Payroll product, part of Oracle E‑Business Suite, is affected in all supported releases from 12.2.3 to 12.2.15. Systems running any of these versions that are reachable over HTTP are vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS 3.1 base score of 8.8, indicating high severity for confidentiality, integrity, and availability. The EPSS score is less than 1 %, suggesting that exploitation is uncommon but still realistic. The vulnerability is not listed in the CISA KEV catalog, so no known widespread exploits are reported. Based on the description, the likely attack vector is network‑based HTTP access, requiring only a low‑privilege account on the network to begin the compromise.

Generated by OpenCVE AI on August 4, 2026 at 00:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Payroll patch released in CPUJul2026 that fixes the internal operations access control flaw
  • Restrict direct HTTP access to the Payroll application to trusted IP addresses or remove the HTTP interface from externally exposed servers
  • Enforce least‑privilege by disabling privileged operations for low‑privilege network accounts within the payroll system

Generated by OpenCVE AI on August 4, 2026 at 00:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Exploit Enables Full Control of Oracle Payroll

Thu, 30 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Remote Exploit Enables Full Control of Oracle Payroll

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Internal Operations Access Control Failure in Oracle Payroll

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Internal Operations Access Control Failure in Oracle Payroll

Wed, 22 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle payroll
CPEs cpe:2.3:a:oracle:payroll:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle payroll
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T17:32:07.011Z

Reserved: 2026-07-14T14:54:48.733Z

Link: CVE-2026-62464

cve-icon Vulnrichment

Updated: 2026-07-22T17:32:00.934Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:00:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function