Sceawere
Vulnerability Detail
CVE-2026-61201Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft CRM Remote Takeover
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise CRM Common Objects
- Attack Type
- Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CRM Common Objects. While the vulnerability is in PeopleSoft Enterprise CRM Common Objects, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CRM Common Objects.
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CRM Common Objects. While the vulnerability is in PeopleSoft Enterprise CRM Common Objects, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CRM Common Objects. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.0",
"pubDate": "2026-07-21T22:18:51.837Z",
"pubdate": "2026-07-21T22:18:51.837Z",
"executiveSummary": "This vulnerability concerns a critical security flaw residing within the Oracle PeopleSoft Enterprise CRM Common Objects component, specifically affecting version 9.2.23. The vulnerability allows an unauthenticated, remote attacker to gain unauthorized control over the affected system via the HTTP protocol.\nClassified with a CVSS 3.1 base score of 9.0, this security defect demonstrates a critical impact on confidentiality, integrity, and availability. Notably, the vulnerability exhibits a scope change (S:C), meaning a successful exploitation can extend beyond the CRM Common Objects component to compromise the underlying infrastructure or interconnected products.\nGiven that the attack vector is network-based and does not require authentication or user interaction, the risk implication is severe. It enables potential full system compromise by unauthorized remote actors, necessitating immediate security assessment and implementation of defensive measures to prevent exploitation.",
"technicalDetails": "The vulnerability resides within the Common Objects component of the PeopleSoft Enterprise CRM suite, specifically identified in version 9.2.23. The flaw is triggered via a network-accessible HTTP interface, which acts as the attack vector. While the primary exposure is within the CRM environment, the scope of the vulnerability is rated as 'Changed,' indicating that the impact of a successful compromise can extend to the broader PeopleSoft environment or the host system, facilitating cross-boundary attacks.\nThe exploitation process initiates over the network using HTTP requests targeting the Common Objects module. Because the vulnerability does not require authentication or user interaction, an attacker can leverage arbitrary, unauthenticated network access to craft and deliver malicious payloads. The complexity of the exploit is categorized as high, suggesting that while the impact is catastrophic, the successful execution of the exploit may rely on specific environmental configurations or precise payload timing to bypass existing security controls.\nUpon successful delivery of a malicious payload to the target component, the vulnerability allows the attacker to execute unauthorized operations with the privileges of the CRM application. The 'takeover' nature of this exploit implies the ability for the attacker to read, modify, or delete sensitive data (Confidentiality and Integrity) and disrupt or crash the service (Availability). Furthermore, because the vulnerability allows for a scope change, an attacker who successfully exploits this entry point can potentially escalate their position to compromise the wider PeopleSoft instance, potentially leading to unauthorized access to system-level functions or the persistence of the attacker within the environment.\nThe root cause points to improper handling or parsing of incoming HTTP requests within the Common Objects component, likely failing to validate or sanitize input before it is processed by the underlying application logic. This lack of rigorous input validation allows the attacker to manipulate the execution flow, leading to arbitrary command execution or unauthorized data manipulation. Post-exploitation, the attacker possesses the capability to establish a foothold within the PeopleSoft architecture, effectively bypassing standard authentication mechanisms that would otherwise protect the system."
}