CVE-2026-46970: Oracle HR Intelligence Privilege Abuse Vulnerability (CVSS 7.2)
Oracle HR Intelligence, a component of Oracle E-Business Suite, contains a vulnerability that allows a privileged network attacker to take control of the system. The flaw affects supported versions 12.2.3 through 12.2.15 and requires the attacker to already have high-level administrative credentials to exploit it. Once exploited, an attacker could compromise confidentiality, integrity, and availability of HR data and system operations.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.2 HIGH · CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Weaknesses (CWE)
- CWE-269
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-17 / 2026-06-18
NVD description (verbatim)
Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HR Intelligence. Successful attacks of this vulnerability can result in takeover of Oracle HR Intelligence. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-46970 is a privilege-abuse vulnerability in Oracle HR Intelligence's Internal Operations component, classified under CWE-269 (Improper Access Control). The vulnerability is network-accessible via HTTP and has low attack complexity, meaning no special conditions are required beyond initial high-privilege authentication. The CVSS 3.1 score of 7.2 reflects high impacts across confidentiality, integrity, and availability—the attacker can read sensitive data, modify records, and disrupt HR operations. The vector (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) indicates network access, no user interaction required, and scope unchanged to the vulnerable component.
Business impact
Compromise of Oracle HR Intelligence poses direct risk to human resources operations and sensitive employee data. An attacker with admin credentials could exfiltrate payroll information, modify employment records, inject false personnel data, or disable HR systems entirely. This affects regulatory compliance (tax reporting, employment verification), operational continuity, and employee trust. Organizations relying on HR Intelligence for critical workflows face potential data breach liabilities and operational disruption.
Affected systems
Oracle E-Business Suite deployments running Oracle HR Intelligence versions 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14, or 12.2.15 are vulnerable. Organizations with extended support for these versions remain at risk until patching is completed. Only E-Business Suite deployments that include the HR Intelligence module are impacted; standalone HR products are not affected.
Exploitability
This vulnerability requires an attacker to already possess high-privilege (administrative) credentials on the E-Business Suite system. The barrier to exploitation is consequently high relative to unauthenticated attacks, but for insiders or attackers who have compromised an admin account, exploitation is straightforward given the low attack complexity and network accessibility. The vulnerability is not currently listed on the CISA KEV catalog, suggesting limited evidence of active exploitation in the wild at the time of publication.
Remediation
Apply the security patch released by Oracle on or shortly after June 17, 2026. Consult Oracle's official security advisory for the exact patch version applicable to your HR Intelligence version. Interim mitigations include restricting network access to HR Intelligence administrative interfaces via firewall rules, disabling HTTP access in favor of HTTPS with client certificate requirements, and auditing admin account usage. Organizations should prioritize patching systems that handle sensitive payroll or personal data.
Patch guidance
Visit Oracle's official security advisory (link to be verified against oracle.com) to identify the specific patch version for your HR Intelligence version within the 12.2.3–12.2.15 range. Test patches in a non-production environment before deployment to ensure compatibility with custom HR processes and integrations. Plan patching around business hours to minimize disruption. Verify successful patch application by confirming the updated component version in Oracle Enterprise Manager or via SQL queries to the database data dictionary.
Detection guidance
Monitor HTTP requests to HR Intelligence administrative endpoints for unusual patterns or high-privilege user activity outside normal business hours. Log all authentication attempts to HR Intelligence accounts, particularly those with admin roles. Inspect for unauthorized modifications to employee records, compensation data, or system configurations. Network-level detection should flag unexpected outbound connections from HR Intelligence servers. Consider implementing database activity monitoring (DAM) to capture changes to sensitive HR tables, which may reveal post-exploitation data exfiltration or modification.
Why prioritize this
Although the CVSS score of 7.2 is high, the requirement for pre-existing high-privilege access significantly reduces immediate risk compared to unauthenticated vulnerabilities. However, organizations should prioritize patching if they have: (1) a large number of HR administrators who could inadvertently be compromised; (2) integration of HR Intelligence with external systems or third-party tools that inherit high privilege; (3) regulatory requirements mandating timely patching of systems handling PII or health information. The lack of KEV listing suggests this is not yet a widespread target, but insider threat models should drive urgency.
Risk score, explained
The CVSS 3.1 base score of 7.2 reflects complete confidentiality, integrity, and availability compromise of the HR Intelligence component itself. The score is elevated by network accessibility and low attack complexity, but constrained by the requirement for high-privilege credentials (PR:H). The score does not account for organizational context—companies with strict admin access controls and network segmentation will face lower practical risk than those with permissive credential distribution. The absence of active exploitation (not on KEV) supports a measured rather than emergency response timeline.
Frequently asked questions
Do I need to patch if I don't use Oracle HR Intelligence?
No. This vulnerability only affects Oracle E-Business Suite systems that have the HR Intelligence module installed and enabled. If your E-Business Suite deployment uses only other modules (e.g., Finance, Procurement), you are not affected. Verify your module inventory in Oracle Enterprise Manager or with your system administrator.
Can this vulnerability be exploited without admin credentials?
No. The vulnerability explicitly requires high-privilege (administrative) access to exploit. Unauthenticated or low-privilege users cannot trigger it. However, if an attacker has compromised an admin account through phishing, credential theft, or another method, they can immediately exploit this flaw.
Is there a workaround if I cannot patch immediately?
Partial mitigation is possible: restrict network access to HR Intelligence via firewall rules to limit admin logins to trusted IP ranges, enforce multi-factor authentication for all HR Intelligence admin accounts, and enable verbose logging and monitoring of admin activity. These measures reduce risk but do not eliminate the vulnerability. Patching remains the only complete fix.
Why is this not on the CISA KEV list if the CVSS is 7.2?
The CISA Known Exploited Vulnerabilities catalog includes only vulnerabilities with evidence of active, widespread exploitation. A high CVSS score alone does not guarantee KEV listing. This vulnerability may lack public proof-of-concept code, active threat intelligence reporting, or incident data at the time of publication. Lack of KEV status does not mean the vulnerability is unimportant—it reflects current exploitation trends, not severity.
This analysis is provided for informational purposes and reflects publicly available data as of the publication date. Patch version numbers and detailed remediation steps must be verified against Oracle's official security advisory at oracle.com. Organizations should conduct their own risk assessment based on their specific HR Intelligence deployment, privilege model, and regulatory obligations. This vulnerability requires pre-existing administrative access; exploit likelihood varies significantly by organization. SEC.co makes no warranty regarding the completeness or accuracy of this analysis and assumes no liability for patching decisions or outcomes. Source: NVD (public-domain), retrieved 2026-07-26. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-35272HIGHOracle PeopleSoft PT PeopleTools Local Privilege Escalation
- CVE-2026-35288HIGHOracle PeopleSoft PeopleTools Privilege Escalation Vulnerability
- CVE-2026-46804HIGHOracle WebCenter Content 14.1.2.0.0 Data Exposure and Modification Vulnerability
- CVE-2026-46827HIGHOracle E-Business Suite Payroll Remote Compromise – 8.8 CVSS
- CVE-2026-46837HIGHOracle Flow Manufacturing SQL Injection & Privilege Escalation
- CVE-2026-46867HIGHOracle Enterprise Manager Base Platform Remote Takeover via Extensibility Framework
- CVE-2026-46873HIGHOracle VM VirtualBox VMSVGA Privilege Escalation (High Severity)
- CVE-2026-46885HIGHOracle Siebel CRM EAI Access Control Vulnerability (CVSS 8.8)