CVE-2026-87161
moderatePrivilege-escalation flaw in Oracle E-Business Suite HRMS (India) 12.2.3-12.2.15
CVE-2026-87161 is a high-severity (CVSS 3.1 base 8.5) authorization flaw in the Internal Operations component of Oracle HRMS (India), part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A low-privileged authenticated attacker with HTTP network access to the E-Business Suite instance can exploit it easily with no user interaction required. Because the vulnerability changes scope, successful attacks may significantly impact additional Oracle E-Business Suite products beyond HRMS (India), resulting in unauthorized access to critical data or complete read access to all HRMS (India)-accessible data, as well as unauthorized update, insert, or delete access to some of that data (high confidentiality impact, low integrity impact, no availability impact). Organizations running affected 12.2.3-12.2.15 deployments that include the India HRMS localization are affected. No public proof-of-concept exists and the CVE is not on the CISA KEV list, so no exploitation is currently known.
What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87161 to all EBS 12.2.3-12.2.15 environments running the HRMS (India) localization, prioritizing internet-facing instances. Restrict HTTP access to the EBS application tier to trusted networks or VPN, and review least-privilege role assignments for low-privileged HRMS accounts. Audit EBS access logs for unexpected bulk data reads or unauthorized insert, update, and delete activity by low-privilege users.
| Oracle E-Business Suite - Oracle HRMS (India) (component: Internal Operations) | 12.2.3-12.2.15 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (India). While the vulnerability is in Oracle HRMS (India), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (India) accessible data as well as unauthorized update, insert or delete access to some of Oracle HRMS (India) accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.