External risk intelligence

Oracle HRMS (UK) Payroll Unauthorized Data Access Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2026-62549

This vulnerability affects a payroll component of an enterprise resource planning suite. While network-reachable via HTTP, Oracle E-Business Suite components like UK Payroll are typically deployed within internal corporate networks for employee and HR use, rather than being exposed directly to the public internet.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in Oracle HRMS (UK), a component of Oracle E-Business Suite, that could allow a low-privileged attacker with network access to modify or access sensitive HR and payroll data. The issue, which has a high severity score, may impact more than just the HRMS (UK) component.

  • A security flaw affects Oracle HRMS (UK) payroll.
  • It could allow unauthorized access to critical data.
  • Confirm relevance and exposure of HRMS (UK) systems.

Attack Path

How an attacker could exploit the issue

An attacker with low privileges can access the Oracle HRMS (UK) component of Oracle E-Business Suite over the network via HTTP. This vulnerability could allow an attacker to modify or delete critical data, or gain complete access to all accessible data within the Oracle HRMS (UK) system, potentially impacting other connected products.

  • Network access, low privileges required.
  • Exploited via HTTP, targeting Oracle HRMS (UK).
  • Unauthorized data modification or access.

Live Threat

Current exploitation, exposure, and threat context

A low-privileged attacker with network access could compromise Oracle HRMS (UK), potentially affecting additional products. This could lead to unauthorized modifications or access to critical data within Oracle HRMS (UK) and other connected systems.

  • Critical payroll and HR data could be affected.
  • Network access via HTTP allows exposure.
  • Unauthorized data modification or access.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Oracle HRMS (UK) product, within Oracle E-Business Suite, is the likely target. Given its critical data access, the first step is to identify all deployments, confirm their business criticality and network reachability, and then engage the accountable owner to plan remediation.

  • Application and infrastructure teams own this.
  • Verify HRMS (UK) deployment and exposure.
  • Plan remediation based on criticality and risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Oracle HRMS (UK) and its role in E-Business Suite?

Oracle HRMS (UK) is a specialized module within the broader Oracle E-Business Suite, designed to manage human resources and payroll operations specifically for organizations operating in the United Kingdom. It serves as a central repository for sensitive employee information, tax calculations, and compensation records. Because it handles complex financial and personal data, it is a critical piece of enterprise infrastructure used by HR and finance departments to ensure regulatory compliance and payroll accuracy.

How does CVE-2026-62549 affect Oracle HRMS (UK)?

CVE-2026-62549 represents a critical security flaw that allows an attacker with low-level system privileges to bypass normal restrictions. In technical terms, it is an authorization-related weakness that enables unauthorized data manipulation or theft. Because it impacts the application layer, an attacker can read, modify, or even delete sensitive payroll data. The vulnerability is also noted for having a scope-changing effect, meaning the impact might extend beyond the payroll component to connected systems.

When can an attacker trigger this vulnerability?

An attacker can trigger this vulnerability if they have existing, low-level network access to the target system via HTTP. It does not require special administrative rights or complex user interactions to initiate the attack. However, simply having access to the network is not enough if the system is properly firewalled; the attack requires specific reachability to the web-based interface of the Oracle HRMS (UK) component to successfully execute the malicious requests.

Do I need to worry about my internal network security?

Yes, even though Halo Surface Signal indicates that Oracle HRMS (UK) is typically deployed within internal corporate networks rather than on the public internet, you should remain vigilant. The vulnerability is classified as network-reachable, meaning that any internal threat actor or compromised device within your corporate environment could potentially reach the payroll module. Assessing the internal segmentation and access controls around these HR systems is essential for minimizing risk.

What is the recommended first step for teams?

Your first step should be to identify all instances of Oracle E-Business Suite running the UK Payroll component. Work with your infrastructure and application teams to confirm which servers are active and determine their network reachability. Once you have an inventory, assess the business criticality of those specific deployments to prioritize them for vendor-supplied updates or security patches as they become available through official Oracle channels.

References