Description
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exploits improper privilege management in Oracle HRMS (US). An attacker with local logon rights on the host running the HRMS can execute actions that grant them full control over the HRMS service. Successful exploitation results in confidentiality, integrity, and availability compromise, effectively allowing the attacker to take over the HRMS application. The weakness is categorized as CWE‑269.

Affected Systems

Oracle Corporation's Oracle HRMS (US) product, part of Oracle E‑Business Suite, is affected. Supported versions 12.2.3 through 12.2.15 are vulnerable. The issue resides in the Internal Operations component of HRMS.

Risk and Exploitability

The CVSS base score is 7.8, indicating high severity. The exploit confidence is low, with an EPSS score of less than 1%, and the vulnerability is not listed in CISA KEV, suggesting limited public exploitation. However, the attack vector requires only local access with low privileges; any user with a login on the host can potentially exploit the flaw. If the method is employed, the attacker can achieve full compromise of the HRMS application.

Generated by OpenCVE AI on August 4, 2026 at 00:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle security patch for HRMS (US) released for versions 12.2.3‑12.2.15 as detailed in Oracle’s July 2026 CPU advisory.
  • Restrict local logon rights for users who do not need to run HRMS, ensuring that only authorized accounts with the minimal privilege required for HRMS operations can access the infrastructure.
  • Enable auditing and monitor for anomalous privilege escalation or unauthorized changes to HRMS configuration.

Generated by OpenCVE AI on August 4, 2026 at 00:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle HRMS (US) via Local Logon Leading to System Takeover

Sat, 01 Aug 2026 04:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in Oracle HRMS (US) via Local Logon Leading to System Takeover

Tue, 28 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Oracle HRMS (US) Local Privilege Escalation Vulnerability Allowing System Takeover

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Oracle HRMS (US) Local Privilege Escalation Vulnerability Allowing System Takeover

Wed, 22 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle HRMS (US) executes to compromise Oracle HRMS (US). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T13:08:37.793Z

Reserved: 2026-07-14T14:54:48.741Z

Link: CVE-2026-62561

cve-icon Vulnrichment

Updated: 2026-07-22T13:08:33.916Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T00:30:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management