CVE-2026-46953: Oracle HRMS (UK) Payroll System Takeover Vulnerability – Severity 7.2
A vulnerability exists in Oracle's HRMS (UK) module within E-Business Suite that allows a privileged network attacker to fully compromise the system. The flaw affects payroll processing for UK organizations running versions 12.2.3 through 12.2.15. An attacker with high-level administrative credentials can exploit this over the network without user interaction, leading to complete takeover of the HRMS system including access to sensitive payroll, employee, and financial data.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-269
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-18
NVD description (verbatim)
Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (UK). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46953 is an improper access control vulnerability (CWE-269) in Oracle HRMS (UK) UK Payroll component. The vulnerability requires high privilege (PR:H) but no attack complexity or user interaction (AC:L, UI:N), and is remotely exploitable via HTTP. The CVSS 3.1 score of 7.2 reflects high impact across confidentiality, integrity, and availability—indicating an attacker can read, modify, or delete data and disrupt service. Affected versions span 12.2.3 through 12.2.15 of Oracle E-Business Suite.
Business impact
Compromise of HRMS (UK) creates severe business continuity and compliance risks. Payroll processing could be halted or corrupted, affecting employee compensation delivery. Sensitive personal data (SSNs, banking, tax information) and financial records become accessible to attackers. UK organizations face regulatory exposure under GDPR and employment law. Reputational damage and potential litigation follow data breaches involving payroll systems. The system's role in financial controls also creates audit and SOX compliance concerns.
Affected systems
Oracle E-Business Suite deployments running HRMS (UK) with payroll functionality, specifically versions 12.2.3 through 12.2.15. Organizations in the UK and those using UK payroll processing with these E-Business Suite releases are affected. Legacy versions within the 12.2.x line remain vulnerable until patched.
Exploitability
Exploitability is limited by the requirement for high-privilege credentials—the attacker must already possess administrative or near-administrative access to the system. However, the absence of attack complexity (AC:L) and the network-accessible nature (AV:N) mean that once a privileged account is compromised or a malicious insider acts, exploitation is straightforward and reliable. This is not a zero-click or unauthenticated attack, but a significant insider threat vector and a stepping stone for lateral movement in compromised environments.
Remediation
Apply the vendor patch from Oracle's Critical Patch Update (CPU) when released. Until patches are available, implement network-level access controls to restrict HTTP access to HRMS (UK) to trusted administrator networks only. Enforce multi-factor authentication for all administrative accounts accessing E-Business Suite. Monitor and audit high-privilege user activity on payroll-related functions. Consider temporarily restricting administrative access to the payroll module for non-essential users.
Patch guidance
Consult Oracle's official Critical Patch Update advisory for June 2026 (or the applicable CPU cycle) for exact patch versions and installation steps specific to your E-Business Suite release. Patches for 12.2.x versions should be tested in a pre-production environment before deployment to payroll systems. Verify patch applicability against your exact version number (12.2.3–12.2.15 are affected) and apply according to Oracle's documented maintenance procedures. Document the patch application in your change management and security logs.
Detection guidance
Monitor HRMS (UK) web server logs for unusual HTTP requests originating from administrative users, particularly those accessing payroll-related endpoints or configuration functions. Alert on any authentication changes to high-privilege accounts in HRMS (UK). Track modifications to payroll data, employee records, or system settings made by administrators outside normal change windows. Use user and entity behavior analytics (UEBA) to detect anomalous administrative activity. Enable audit logging in E-Business Suite and review logs for privilege escalation or unusual data access patterns within the payroll module.
Why prioritize this
This vulnerability should be prioritized for any organization running the affected HRMS (UK) versions due to the high CVSS score (7.2) and broad impact on confidentiality, integrity, and availability. The insider threat context—high-privilege requirement—means your security posture depends heavily on administrator account hygiene and network segmentation. UK organizations face additional regulatory urgency due to data protection and employment law obligations. Payroll systems are often targeted by attackers and insiders; compromise directly threatens employee welfare and organizational stability.
Risk score, explained
The CVSS 3.1 base score of 7.2 (HIGH) reflects three factors: (1) Network accessibility (AV:N) broadens potential attack surface; (2) Low attack complexity (AC:L) and no user interaction (UI:N) mean exploitation is reliable once a privileged account is obtained; (3) Full impact across confidentiality, integrity, and availability (C:H, I:H, A:H) indicates complete system compromise. The high-privilege requirement (PR:H) prevents a 9.0+ score but does not mitigate the severity—privileged accounts are frequent targets and insider threats. Environmental factors (data sensitivity, regulatory obligations) should raise priority further in your risk assessment.
Frequently asked questions
Why does this vulnerability require high privilege? Isn't that less dangerous?
High privilege is a limiting factor for exploitability, but it does not eliminate the risk. Privileged credentials are stolen, shared, or abused by insiders regularly. In multi-tenant or contractor environments, privilege scope creep is common. Once exploited, the attacker gains complete control over payroll and HR data—a high-value target. Your defense strategy should focus on strong authentication, access auditing, and network segmentation around administrative functions.
We run Oracle E-Business Suite but are unsure of our exact HRMS (UK) version. How do we check?
Log into your E-Business Suite environment and navigate to Help > About Oracle Applications to view the version and patch level. Alternatively, query the database using the query: SELECT RELEASE_NAME FROM FND_PRODUCT_GROUPS. Your database administrator or system administrator can retrieve this information. Once you confirm your version, cross-reference it against the affected range (12.2.3–12.2.15) to determine if you are in scope.
Are we affected if we use HRMS but not the UK Payroll module?
This vulnerability is specific to the UK Payroll component within HRMS (UK). If your organization uses Oracle HRMS but has not deployed the UK-specific payroll functionality, the risk is lower; however, if you have the module installed but inactive, verify with Oracle and apply patches proactively. Do not assume non-US payroll implementations are unaffected—review the exact component scope in Oracle's patch advisory.
What should we do immediately while waiting for a patch?
Implement network-level restrictions to limit HTTP access to HRMS (UK) to specific trusted administrator networks or jump hosts. Enable multi-factor authentication for all accounts with access to the payroll module. Audit current high-privilege account assignments and disable or restrict unused accounts. Enable comprehensive audit logging in E-Business Suite and monitor for unusual administrative activity. Schedule a pre-production patch test cycle now so you can deploy rapidly once Oracle releases the fix.
This analysis is based on the official CVE-2026-46953 description and CVSS metrics published as of June 2026. Patch version numbers and exact remediation steps must be verified against Oracle's official Critical Patch Update advisory; this document does not provide specific patch versions. Organizations should validate their system inventory, test patches in non-production environments, and consult Oracle Support for their specific configuration. SEC.co provides this information for security planning purposes; individual risk assessment and regulatory compliance obligations are the responsibility of each organization. Source: NVD (public-domain), retrieved 2026-07-26. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35272HIGHOracle PeopleSoft PT PeopleTools Local Privilege Escalation
- CVE-2026-35288HIGHOracle PeopleSoft PeopleTools Privilege Escalation Vulnerability
- CVE-2026-46804HIGHOracle WebCenter Content 14.1.2.0.0 Data Exposure and Modification Vulnerability
- CVE-2026-46827HIGHOracle E-Business Suite Payroll Remote Compromise – 8.8 CVSS
- CVE-2026-46837HIGHOracle Flow Manufacturing SQL Injection & Privilege Escalation
- CVE-2026-46867HIGHOracle Enterprise Manager Base Platform Remote Takeover via Extensibility Framework
- CVE-2026-46873HIGHOracle VM VirtualBox VMSVGA Privilege Escalation (High Severity)
- CVE-2026-46885HIGHOracle Siebel CRM EAI Access Control Vulnerability (CVSS 8.8)