Description
Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Internal Operations component of Oracle Public Sector Payroll within Oracle E‑Business Suite. It permits an attacker with low level credentials and network access via HTTP to compromise the application, potentially gaining full control. The flaw allows an attacker to elevate privileges, modify access controls, and execute authentication bypass, leading to significant confidentiality, integrity and availability loss as reflected in the CVSS 3.1 Base Score of 8.8.

Affected Systems

Oracle Public Sector Payroll in versions 12.2.3 through 12.2.15 of Oracle E‑Business Suite is affected. No other vendors or products are listed.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity risk, yet the EPSS score of less than 1% and absence from the CISA KEV catalog suggest exploitation is currently rare. Inferred the attack vector is an unauthenticated or low‑privileged HTTP request that bypasses normal authentication. Successful exploitation would allow a user to take over or corrupt payroll data, impacting all users and potentially the organization’s financial operations.

Generated by OpenCVE AI on August 4, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Oracle or apply the latest vendor patch when it becomes available
  • Restrict HTTP access to the Payroll application to trusted IP ranges or through a firewall
  • Enforce least privilege by disabling or restricting low‑privileged accounts that can authenticate to the system

Generated by OpenCVE AI on August 4, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Complete Payroll System Takeover

Sun, 02 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title Low-Privilege HTTP Exploit Enables Complete Payroll System Takeover

Tue, 28 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation in Oracle Public Sector Payroll Via Internal Operations Flaw

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation in Oracle Public Sector Payroll Via Internal Operations Flaw

Wed, 22 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-287
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle public Sector Payroll
CPEs cpe:2.3:a:oracle:public_sector_payroll:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle public Sector Payroll
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Public Sector Payroll
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T16:31:40.115Z

Reserved: 2026-07-14T14:54:48.734Z

Link: CVE-2026-62476

cve-icon Vulnrichment

Updated: 2026-07-22T16:31:33.632Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T16:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function