ZeroHour

CVE-2026-87124

moderate

Authenticated Data Exposure in Oracle iRecruitment (E-Business Suite 12.2)

CVSS 3.1
7.7 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87124 is an easily exploitable vulnerability in the Internal Operations component of Oracle iRecruitment, a recruitment/hiring module of Oracle E-Business Suite, affecting versions 12.2.3 through 12.2.15. It is triggered by a low-privileged, authenticated attacker sending requests over HTTP to the iRecruitment web tier, requiring no user interaction. Successful exploitation yields unauthorized access to critical data or complete access to all data reachable through Oracle iRecruitment, and because the vulnerability has a scope change, successful attacks may significantly impact products beyond iRecruitment itself. Organizations running E-Business Suite 12.2.3-12.2.15 with iRecruitment enabled — particularly those exposing the module to applicants or employees over the internet — are affected. No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation has been reported to date.

What to do: Apply the Oracle Critical Patch Update that remediates this flaw to all E-Business Suite 12.2.3-12.2.15 environments running iRecruitment. Restrict HTTP access to iRecruitment and internal-operations pages via VPN or IP allowlisting, since only a low-privileged account (e.g., employee or applicant self-service login) is needed to exploit the flaw. Review EBS audit logs for anomalous data access by low-privilege accounts against recruitment data.

Affected
Oracle iRecruitment (Oracle E-Business Suite), component: Internal Operations12.2.3 - 12.2.15
Estimated exposure
moderatelow thousands of potentially internet-exposed instances (roughly 1,000-10,000 EBS 12.2 deployments running iRecruitment) — Public internet scans have historically shown thousands to low tens of thousands of internet-facing Oracle E-Business Suite endpoints, and iRecruitment self-service portals are commonly exposed by design; no vendor install counts exist, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment. While the vulnerability is in Oracle iRecruitment, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.