CVE-2026-61121
Oracle · Oracle HRMS (UK)
A vulnerability in the UK Payroll component of Oracle HRMS (UK) permits a low privileged attacker to compromise the application through network-based HTTP exploitation.
Executive summary
This high severity vulnerability in Oracle HRMS (UK) enables an authenticated attacker to achieve total system compromise.
Vulnerability
This is an easily exploitable flaw affecting the UK Payroll component. It requires the attacker to possess low privileges and network access to the target system to facilitate a takeover.
Business impact
The CVSS score of 8.8 highlights the critical nature of this flaw. Exploitation could lead to the unauthorized access of sensitive human resources data and the potential for total takeover of the Oracle HRMS platform, resulting in severe compliance and reputational risks for the organization.
Remediation
Immediate Action: Apply the relevant security updates released in the July 2026 Oracle Critical Patch Update.
Proactive Monitoring: Monitor for unusual query patterns or administrative commands originating from low-level user accounts within the UK Payroll module.
Compensating Controls: Utilize a Web Application Firewall to restrict access to the HRMS interface and block potentially malicious HTTP payloads.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Urgent attention is required to secure the Oracle HRMS (UK) environment. Organizations should immediately review the July 2026 Oracle security advisory and schedule the application of the required patches to prevent potential system exploitation.