Sceawere
Vulnerability Detail
CVE-2026-61072Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft Staffing Remote Compromise
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Staffing Front Office Brazil
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office Brazil. While the vulnerability is in PeopleSoft Enterprise FIN Staffing Front Office Brazil, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Staffing Front Office Brazil.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise FIN Staffing Front Office Brazil product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Staffing Front Office Brazil. While the vulnerability is in PeopleSoft Enterprise FIN Staffing Front Office Brazil, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Staffing Front Office Brazil. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-07-21T22:18:37.980Z",
"pubdate": "2026-07-21T22:18:37.980Z",
"executiveSummary": "This vulnerability affects the Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil product, specifically version 9.1.\nThe flaw allows a low-privileged, remote attacker to achieve a full system takeover through the HTTP protocol.\nThe vulnerability is characterized by a significant scope change, indicating that successful exploitation can lead to a compromise beyond the immediate Staffing component, potentially affecting the broader PeopleSoft infrastructure.\nWith a CVSS 3.1 Base Score of 9.9, the vulnerability carries a critical risk rating, reflecting its ease of exploitation, lack of required user interaction, and comprehensive impact on the confidentiality, integrity, and availability of the affected system.\nThe attack vector is network-based, meaning any attacker with established network connectivity to the PeopleSoft environment can potentially execute malicious payloads, provided they possess low-privileged credentials.",
"technicalDetails": "The vulnerability resides within the Staffing component of PeopleSoft Enterprise FIN Staffing Front Office Brazil version 9.1. It manifests as a high-severity flaw that enables unauthorized remote code execution or complete system takeover via standard HTTP request structures.\nThe attack flow initiates when a low-privileged authenticated attacker sends a crafted malicious HTTP request to the vulnerable Staffing module. Due to insufficient input validation or insecure handling of application logic within the component, the application fails to restrict the attacker's actions, allowing them to bypass access controls.\nThe exploitation process leverages the application's network exposure. Because the vulnerability involves a scope change (S:C), the attacker is not confined to the Staffing component itself; the compromise can escalate to the underlying application server, database, or associated PeopleSoft middleware services.\nTechnical root causes typically involve improper handling of serialized objects, unsafe deserialization, or flaws in the application's business logic that allow for arbitrary command or code execution. Once the malicious payload is transmitted over HTTP, the server processes the request with elevated privileges, granting the attacker the ability to execute unauthorized commands or manipulate system state.\nPost-exploitation, the impact is comprehensive. An attacker achieving this level of control can exfiltrate sensitive data (Confidentiality impact), modify or destroy financial records or application configurations (Integrity impact), and disrupt the availability of critical business services (Availability impact). Given the integration requirements of PeopleSoft, the ability to pivot from the Staffing component to the wider enterprise environment presents a substantial security risk to the entire PeopleSoft stack.\nThe CVSS 3.1 vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) confirms that the vulnerability is easily exploitable (AC:L) without requiring user interaction (UI:N), necessitating immediate attention to secure the network perimeter and application-level access controls."
}