Sceawere

Vulnerability Detail

CVE-2026-61072Updated Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft Staffing Remote Compromise

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
4h ago
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Staffing Front Office Brazil
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office Brazil. While the vulnerability is in PeopleSoft Enterprise FIN Staffing Front Office Brazil, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Staffing Front Office Brazil.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office Brazil. While the vulnerability is in PeopleSoft Enterprise FIN Staffing Front Office Brazil, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Staffing Front Office Brazil. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-07-21T22:18:37.980Z",
  "pubdate": "2026-07-21T22:18:37.980Z",
  "executiveSummary": "This vulnerability affects the Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil product, specifically version 9.1.\nThe flaw allows a low-privileged, remote attacker to achieve a full system takeover through the HTTP protocol.\nThe vulnerability is characterized by a significant scope change, indicating that successful exploitation can lead to a compromise beyond the immediate Staffing component, potentially affecting the broader PeopleSoft infrastructure.\nWith a CVSS 3.1 Base Score of 9.9, the vulnerability carries a critical risk rating, reflecting its ease of exploitation, lack of required user interaction, and comprehensive impact on the confidentiality, integrity, and availability of the affected system.\nThe attack vector is network-based, meaning any attacker with established network connectivity to the PeopleSoft environment can potentially execute malicious payloads, provided they possess low-privileged credentials.",
  "technicalDetails": "The vulnerability resides within the Staffing component of PeopleSoft Enterprise FIN Staffing Front Office Brazil version 9.1. It manifests as a high-severity flaw that enables unauthorized remote code execution or complete system takeover via standard HTTP request structures.\nThe attack flow initiates when a low-privileged authenticated attacker sends a crafted malicious HTTP request to the vulnerable Staffing module. Due to insufficient input validation or insecure handling of application logic within the component, the application fails to restrict the attacker's actions, allowing them to bypass access controls.\nThe exploitation process leverages the application's network exposure. Because the vulnerability involves a scope change (S:C), the attacker is not confined to the Staffing component itself; the compromise can escalate to the underlying application server, database, or associated PeopleSoft middleware services.\nTechnical root causes typically involve improper handling of serialized objects, unsafe deserialization, or flaws in the application's business logic that allow for arbitrary command or code execution. Once the malicious payload is transmitted over HTTP, the server processes the request with elevated privileges, granting the attacker the ability to execute unauthorized commands or manipulate system state.\nPost-exploitation, the impact is comprehensive. An attacker achieving this level of control can exfiltrate sensitive data (Confidentiality impact), modify or destroy financial records or application configurations (Integrity impact), and disrupt the availability of critical business services (Availability impact). Given the integration requirements of PeopleSoft, the ability to pivot from the Staffing component to the wider enterprise environment presents a substantial security risk to the entire PeopleSoft stack.\nThe CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) confirms that the vulnerability is easily exploitable (AC:L) without requiring user interaction (UI:N), necessitating immediate attention to secure the network perimeter and application-level access controls."
}
CVE-2026-61072: PeopleSoft Staffing Remote Compromise (CRITICAL Severity, CVSS: 9.9) - Sceawere