Sceawere

Vulnerability Detail

CVE-2026-61076Updated Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft HCM Critical Compromise

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
4h ago
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise HCM Talent Acquisition Manager
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent Acquisition Manager. While the vulnerability is in PeopleSoft Enterprise HCM Talent Acquisition Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Talent Acquisition Manager.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent Acquisition Manager. While the vulnerability is in PeopleSoft Enterprise HCM Talent Acquisition Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Talent Acquisition Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-07-21T22:18:38.410Z",
  "pubdate": "2026-07-21T22:18:38.410Z",
  "executiveSummary": "This vulnerability affects the Job Opening component within Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager version 9.2.\nThe vulnerability is classified as a critical security flaw with a CVSS 3.1 base score of 9.9, indicating severe risks to confidentiality, integrity, and availability.\nThe flaw allows a low-privileged, remote attacker with network access via HTTP to fully compromise the application.\nDue to the nature of the vulnerability, a scope change is possible, enabling an attacker to compromise systems beyond the Talent Acquisition Manager module, potentially leading to a complete system takeover.\nThe exploit requires minimal effort due to its low attack complexity and does not require user interaction, making it a high-priority threat for organizations utilizing PeopleSoft Enterprise HCM.",
  "technicalDetails": "The vulnerability resides within the Job Opening component of the Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager, specifically affecting version 9.2.\nThe attack vector is characterized as network-based, utilizing the HTTP protocol, which permits remote exploitation without the necessity of physical access or local authentication beyond a low-privileged account.\nThe CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) confirms that the vulnerability is easily exploitable (low complexity) and does not require user interaction (UI:N).\nThe most significant aspect of this vulnerability is the scope change (S:C). This indicates that the vulnerability allows an attacker to transition from the compromised Job Opening component to broader environments or peripheral systems integrated with the PeopleSoft Enterprise HCM architecture.\nAn attacker initiates the exploitation by crafting malicious HTTP requests directed at the Job Opening component. Because the component fails to properly validate or sanitize the input from a low-privileged user, the attacker can execute unauthorized actions or inject payloads that bypass established security controls.\nOnce the initial point of entry is achieved, the lack of robust boundary enforcement within the component allows the attacker to escalate privileges or move laterally. The compromise of the Job Opening component provides the necessary leverage to execute arbitrary commands or manipulate data directly within the PeopleSoft backend.\nGiven the high impact on Confidentiality (C:H), Integrity (I:H), and Availability (A:H), the exploitation results in a full system takeover. An attacker can exfiltrate sensitive candidate or employee data (Confidentiality), modify or delete critical recruitment records (Integrity), and disrupt service availability through denial-of-service or configuration destruction (Availability).\nFurthermore, the scope change implication suggests that the attacker can potentially pivot to the application server or the underlying database layer, effectively granting them full administrative control over the PeopleSoft environment. The technical root cause pertains to insufficient authorization or input validation controls within the Job Opening component's HTTP request handling logic, which is insufficient to prevent a low-privileged actor from performing high-privilege operations."
}
CVE-2026-61076: PeopleSoft HCM Critical Compromise (CRITICAL Severity, CVSS: 9.9) - Sceawere