CVE-2026-46955
Awaiting Analysis Awaiting Analysis - Queue
Oracle Human Resources Takeover via HTTP

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Oracle

Description
Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Human Resources. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
oracle human_resources From 12.2.3 (inc) to 12.2.15 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the Oracle Human Resources product of the Oracle E-Business Suite, specifically affecting versions 12.2.3 through 12.2.15. It is a difficult to exploit vulnerability that allows an unauthenticated attacker with network access via HTTP to potentially compromise the Oracle Human Resources system. However, successful exploitation requires human interaction from someone other than the attacker.

If successfully exploited, the attacker can take over the Oracle Human Resources component.

Impact Analysis

The impact of this vulnerability includes a potential takeover of the Oracle Human Resources system, which can affect confidentiality, integrity, and availability of the system.

  • Confidentiality impact: sensitive HR data could be exposed.
  • Integrity impact: unauthorized changes to HR data or system settings could occur.
  • Availability impact: the HR system could be disrupted or made unavailable.
Compliance Impact

The vulnerability in Oracle Human Resources allows an unauthenticated attacker to potentially take over the system, impacting confidentiality, integrity, and availability. Such a compromise could lead to unauthorized access to sensitive personal data managed by the Human Resources system.

Because of the high impact on confidentiality and integrity, this vulnerability could negatively affect compliance with data protection regulations such as GDPR and HIPAA, which require safeguarding personal and health information against unauthorized access and breaches.

However, the provided information does not explicitly mention compliance implications or specific regulatory impacts.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-46955. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart