Description
Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). While the vulnerability is in Oracle HRMS (US), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-08-18
Score: 8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in Oracle HRMS (US) of Oracle E‑Business Suite, specifically in the US Payroll – General component. The flaw allows an attacker who already has high privileged network access via HTTP to take over the HRMS (US) instance. Successful exploitation gives the attacker control over the system, resulting in full confidentiality, integrity and availability compromise for the affected HRMS components. The CVSS 3.1 base score of 8.0 reflects the severe impact on all three security objectives.

Affected Systems

Affected vendors include Oracle Corporation, product Oracle HRMS (US). The impacted product range is Oracle E‑Business Suite HRMS versions 12.2.3 through 12.2.15. The vulnerability resides in the US Payroll – General module, and due to a scope change, related Oracle products could also be impacted. Only the US region deployment of HRMS is listed as affected, and no other vendors or products are cited.

Risk and Exploitability

The CVSS score of 8.0 indicates a high severity threat. Exploitability is classified as difficult, requiring an attacker to possess high privileged access and to reach the system over HTTP. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation yet. Nonetheless, the combination of high impact and the ability to compromise HRMS (US) warrants close monitoring and swift remediation. The vector requires network access in an internal or trusted environment, so securing HTTP interfaces and limiting privileged accounts are critical mitigation points.

Generated by OpenCVE AI on August 19, 2026 at 01:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Refer to Oracle’s security advisory for the latest patch updates and download the appropriate service pack for Oracle HRMS (US) versions 12.2.3‑12.2.15
  • Apply the patch or service pack to all instances of Oracle HRMS (US) before the end of the patching cycle
  • Restrict HTTP access to Oracle HRMS (US) to authorized users only, preferably over an isolated network segment or VPN, and enforce strict authentication and least‑privilege rules

Generated by OpenCVE AI on August 19, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Oracle HRMS (US) Remote Privilege Escalation Over HTTP
Weaknesses CWE-284

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Suite (component: US Payroll - General). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (US). While the vulnerability is in Oracle HRMS (US), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (US). CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle hrms
CPEs cpe:2.3:a:oracle:hrms:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle hrms
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T21:01:01.949Z

Reserved: 2026-08-04T22:06:34.589Z

Link: CVE-2026-70690

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:17:20.990

Modified: 2026-08-18T21:17:20.990

Link: CVE-2026-70690

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T01:30:05Z

Weaknesses