CVE-2026-87159
moderateBroken Access Control in Oracle E-Business Suite HRMS (India) 12.2.3-12.2.15
A high-severity (CVSS 8.1) authorization flaw in the Internal Operations component of Oracle HRMS (India), part of Oracle E-Business Suite, allows a low-privileged authenticated attacker with HTTP network access to compromise the product. Exploitation is described by Oracle as easy: a valid low-privilege account sends crafted requests over the network, with no user interaction required. A successful attack yields unauthorized creation, deletion, or modification of critical data, as well as full read access to all data accessible to Oracle HRMS (India) — potentially sensitive payroll, personnel, and localization data. Organizations running E-Business Suite release 12.2.3 through 12.2.15 with the India HRMS localization are affected. No public proof-of-concept exists and the flaw is not on the CISA KEV catalog, so exploitation in the wild is not currently indicated.
What to do: Apply Oracle's Critical Patch Update containing the fix for CVE-2026-87159 to all E-Business Suite 12.2.3-12.2.15 environments running HRMS (India). Restrict HTTP access to EBS so the self-service and HRMS modules are not reachable from untrusted networks, and enforce least-privilege roles for EBS user accounts. Review audit logs for unexpected data changes or record access by low-privilege accounts in the HRMS (India) schemas.
| Oracle HRMS (India) (Oracle E-Business Suite, component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (India). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (India) accessible data as well as unauthorized access to critical data or complete access to all Oracle HRMS (India) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.