Sceawere
Vulnerability Detail
CVE-2026-61204Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft Primavera Integration RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Program Management
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Program Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Program Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Program Management.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Program Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Program Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Program Management. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.0",
"pubDate": "2026-07-21T22:18:52.180Z",
"pubdate": "2026-07-21T22:18:52.180Z",
"executiveSummary": "This vulnerability affects the Primavera Integration component within Oracle PeopleSoft Enterprise FIN Program Management version 9.2.\nThe flaw allows a low-privileged authenticated attacker to achieve a full system compromise through a network-based attack vector.\nSuccessful exploitation results in a complete takeover of the affected product, including impacts on confidentiality, integrity, and availability.\nThe vulnerability is characterized by a scope change (S:C), meaning a successful exploit can facilitate unauthorized access or control over additional integrated products beyond the immediate component.\nExploitation requires human interaction from a legitimate user and is easily executable, making it a critical risk for organizations utilizing these specific integrations.\nGiven the CVSS 3.1 base score of 9.0, the vulnerability represents an critical threat to enterprise security architectures.",
"technicalDetails": "The vulnerability resides within the Primavera Integration component of PeopleSoft Enterprise FIN Program Management 9.2, exposing a critical security flaw in the integration layer.\nThe attack vector is identified as network-based (AV:N), utilizing HTTP protocols to interact with the target system. The attack complexity is rated as low (AC:L), indicating that minimal technical barriers exist for an attacker to craft a functional exploit.\nA prerequisite for exploitation is the presence of an authenticated low-privileged user; however, the attack requires the targeted user to perform a specific action (UI:R), typically clicking a malicious link or interacting with a crafted interface element.\nThe vulnerability exhibits a scope change (S:C), which is the most critical aspect of this flaw. This indicates that the exploitation of the Primavera Integration component can bypass security boundaries, potentially leading to the compromise of the broader Oracle PeopleSoft environment or secondary systems integrated with the Program Management suite.\nThe exploitation flow begins with an attacker delivering a payload via HTTP to the vulnerable component, relying on the user interaction requirement to trigger the malicious request within the context of an authenticated session.\nUpon successful execution, the payload facilitates arbitrary code execution or command injection, resulting in a full system takeover (C:H/I:H/A:H). Because the exploit bypasses the initial component's privilege restrictions, the attacker gains the authority of the authenticated session, often escalating to administrative control.\nThe post-exploitation impact includes unauthorized data exfiltration, modification of critical financial or programmatic data, and total loss of system availability. The integration-heavy nature of the Primavera module implies that once the component is compromised, the attacker can leverage existing trust relationships to propagate the breach into other enterprise systems, effectively neutralizing internal segmentation controls."
}