ZeroHour

CVE-2026-87161

moderate

Privilege-escalation flaw in Oracle E-Business Suite HRMS (India) 12.2.3-12.2.15

CVSS 3.1
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-87161 is a high-severity (CVSS 3.1 base 8.5) authorization flaw in the Internal Operations component of Oracle HRMS (India), part of Oracle E-Business Suite releases 12.2.3 through 12.2.15. A low-privileged authenticated attacker with HTTP network access to the E-Business Suite instance can exploit it easily with no user interaction required. Because the vulnerability changes scope, successful attacks may significantly impact additional Oracle E-Business Suite products beyond HRMS (India), resulting in unauthorized access to critical data or complete read access to all HRMS (India)-accessible data, as well as unauthorized update, insert, or delete access to some of that data (high confidentiality impact, low integrity impact, no availability impact). Organizations running affected 12.2.3-12.2.15 deployments that include the India HRMS localization are affected. No public proof-of-concept exists and the CVE is not on the CISA KEV list, so no exploitation is currently known.

What to do: Apply the Oracle Critical Patch Update that remediates CVE-2026-87161 to all EBS 12.2.3-12.2.15 environments running the HRMS (India) localization, prioritizing internet-facing instances. Restrict HTTP access to the EBS application tier to trusted networks or VPN, and review least-privilege role assignments for low-privileged HRMS accounts. Audit EBS access logs for unexpected bulk data reads or unauthorized insert, update, and delete activity by low-privilege users.

Affected
Oracle E-Business Suite - Oracle HRMS (India) (component: Internal Operations)12.2.3-12.2.15
Estimated exposure
moderateLikely low thousands of enterprise deployments (subset of Oracle EBS 12.2 sites running the India HRMS localization) — Oracle E-Business Suite is deployed at tens of thousands of organizations worldwide, but the India-specific HRMS localization restricts exposure to organizations with Indian HR/payroll operations on EBS 12.2; exact counts are not public,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (India). While the vulnerability is in Oracle HRMS (India), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle HRMS (India) accessible data as well as unauthorized update, insert or delete access to some of Oracle HRMS (India) accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).

Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

In the news

No ingested article mentions this CVE yet.