Sceawere

Vulnerability Detail

CVE-2026-61204Updated Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft Primavera Integration RCE

Vulnerability Metadata

Severity
Critical
Score / CVSS
9
Creation Date
4h ago
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Program Management
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Program Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Program Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Program Management.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Program Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Program Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Program Management. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.0",
  "pubDate": "2026-07-21T22:18:52.180Z",
  "pubdate": "2026-07-21T22:18:52.180Z",
  "executiveSummary": "This vulnerability affects the Primavera Integration component within Oracle PeopleSoft Enterprise FIN Program Management version 9.2.\nThe flaw allows a low-privileged authenticated attacker to achieve a full system compromise through a network-based attack vector.\nSuccessful exploitation results in a complete takeover of the affected product, including impacts on confidentiality, integrity, and availability.\nThe vulnerability is characterized by a scope change (S:C), meaning a successful exploit can facilitate unauthorized access or control over additional integrated products beyond the immediate component.\nExploitation requires human interaction from a legitimate user and is easily executable, making it a critical risk for organizations utilizing these specific integrations.\nGiven the CVSS 3.1 base score of 9.0, the vulnerability represents an critical threat to enterprise security architectures.",
  "technicalDetails": "The vulnerability resides within the Primavera Integration component of PeopleSoft Enterprise FIN Program Management 9.2, exposing a critical security flaw in the integration layer.\nThe attack vector is identified as network-based (AV:N), utilizing HTTP protocols to interact with the target system. The attack complexity is rated as low (AC:L), indicating that minimal technical barriers exist for an attacker to craft a functional exploit.\nA prerequisite for exploitation is the presence of an authenticated low-privileged user; however, the attack requires the targeted user to perform a specific action (UI:R), typically clicking a malicious link or interacting with a crafted interface element.\nThe vulnerability exhibits a scope change (S:C), which is the most critical aspect of this flaw. This indicates that the exploitation of the Primavera Integration component can bypass security boundaries, potentially leading to the compromise of the broader Oracle PeopleSoft environment or secondary systems integrated with the Program Management suite.\nThe exploitation flow begins with an attacker delivering a payload via HTTP to the vulnerable component, relying on the user interaction requirement to trigger the malicious request within the context of an authenticated session.\nUpon successful execution, the payload facilitates arbitrary code execution or command injection, resulting in a full system takeover (C:H/I:H/A:H). Because the exploit bypasses the initial component's privilege restrictions, the attacker gains the authority of the authenticated session, often escalating to administrative control.\nThe post-exploitation impact includes unauthorized data exfiltration, modification of critical financial or programmatic data, and total loss of system availability. The integration-heavy nature of the Primavera module implies that once the component is compromised, the attacker can leverage existing trust relationships to propagate the breach into other enterprise systems, effectively neutralizing internal segmentation controls."
}
CVE-2026-61204: PeopleSoft Primavera Integration RCE (CRITICAL Severity, CVSS: 9.0) - Sceawere