HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-46953Published Modified CNA oracle

CVE-2026-46953: Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll)

Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (UK). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Metrics

CVSS v3.1
7.2
Severity
HIGH
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a high-severity vulnerability in the UK Payroll component of Oracle HRMS (UK), part of Oracle E-Business Suite versions 12.2.3 through 12.2.15. An attacker with administrative credentials can reach the affected component over the network via HTTP and exploit it without any victim interaction. Successful exploitation results in full takeover of the Oracle HRMS (UK) instance, giving the attacker read, write, and denial-of-service capability over the system. No fix version has been published by Oracle; HarborGuard is tracking the advisory and will make a patched rebuild available the moment upstream ships a fix.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against customer images, including custom-built images that layer Oracle E-Business Suite components. Any image running an affected version of Oracle HRMS (UK) (12.2.3 through 12.2.15) is flagged automatically.

Available
Triage

HarborGuard scores this finding at CVSS 7.2 HIGH and weights it against each environment's compliance policy, escalating to the appropriate team inbox within the customer org. Per-environment policy configuration allows security and platform teams to set breach thresholds that determine whether the finding blocks a pipeline stage or triggers an alert-only workflow.

Available
Patch

No fix version has been published by Oracle for this CVE. HarborGuard re-checks the advisory on every ingest cycle and will make a patched-image rebuild available automatically the moment Oracle publishes a corrected release. For customers who opt into auto-remediation, the rebuild, regression run, and PR against affected workloads will be initiated without manual intervention as soon as a fix version becomes available.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Oracle HRMS (UK) service over the network via HTTP; there is no local-only attack path.

  • AuthenticationRequired

    A high-privileged (administrative) account is required; the vulnerability is not exploitable by unauthenticated users or low-privilege accounts.

  • Victim interactionNot required

    No victim action such as clicking a link or opening a file is needed; the attacker can exploit the service directly.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory layout knowledge, or other environmental factors to succeed.

Blast Radius

  • A successful attacker reads all data accessible to the Oracle HRMS (UK) application, including payroll records, employee personal data, and stored credentials.
  • The attacker can modify or delete persisted payroll and HR records, including salary figures, tax codes, and employee banking details.
  • The attacker can crash or render the Oracle HRMS (UK) service unavailable, blocking payroll processing and HR operations.
  • Full application takeover means the attacker can install backdoors or pivot to other systems that trust the Oracle E-Business Suite application tier.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for CVE-2026-46953, the primary capability is continuous advisory monitoring. HarborGuard re-evaluates the upstream Oracle and NVD feeds on every ingest cycle and will trigger a patched-image rebuild automatically the moment a fix version is released; customers with auto-remediation enabled will receive the rebuild, a regression test run, and a PR opened against affected workloads with no manual steps required. In the interim, compensating controls worth evaluating include network-policy isolation that restricts HTTP access to the UK Payroll component to only known, authorized IP ranges; egress filtering to limit the application tier's outbound connectivity; and disabling or gating any non-essential UK Payroll features via application-level feature flags if Oracle provides that option. Given the CVSS 7.2 HIGH score and the administrative-access requirement, prioritize auditing which accounts hold elevated Oracle E-Business Suite privileges and rotating or tightening those credentials while the upstream fix is pending.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle HRMS (UK)
    ≤ 12.2.15
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References