Sceawere

Vulnerability Detail

CVE-2026-61209Updated Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft Project Discovery Critical Takeover

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
4h ago
Vendor
Oracle Corporation
Product
PeopleSoft In-Memory Project Discovery
Attack Type
Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery. While the vulnerability is in PeopleSoft In-Memory Project Discovery, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft In-Memory Project Discovery.
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery. While the vulnerability is in PeopleSoft In-Memory Project Discovery, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft In-Memory Project Discovery. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-07-21T22:18:52.560Z",
  "pubdate": "2026-07-21T22:18:52.560Z",
  "executiveSummary": "The Oracle PeopleSoft In-Memory Project Discovery component in version 9.2 is susceptible to a critical security vulnerability that permits unauthorized actors to achieve full system compromise.\nCategorized with a CVSS 3.1 Base Score of 9.9, this flaw enables a low-privileged attacker to execute unauthorized operations via HTTP, leading to a complete takeover of the affected component.\nThe vulnerability is characterized by a scope change (S:C), meaning that while the primary flaw exists within the Project Discovery module, the potential impact extends to surrounding infrastructure and integrated products.\nDue to the nature of the vulnerability, an attacker requires minimal access—specifically network reachability and low-level credentials—to exploit the system without user interaction.\nThe combination of high confidentiality, integrity, and availability impact signifies that successful exploitation could lead to total data exposure, unauthorized modification of sensitive project configurations, and denial-of-service, posing a severe risk to the entire PeopleSoft environment.",
  "technicalDetails": "The vulnerability resides within the Project Discovery component of Oracle PeopleSoft version 9.2, allowing for unauthorized remote execution. The technical severity is driven by the ability of an authenticated, low-privileged user to leverage network-accessible HTTP endpoints to bypass inherent security controls within the application architecture.\nThe attack flow commences with an attacker establishing a network connection to the target PeopleSoft instance. Because the vulnerability is remotely exploitable over HTTP with low-privilege requirements (PR:L), the attacker does not need high-level administrative rights to initiate the chain. By interacting with the Project Discovery interface, the attacker can submit specially crafted requests that the application fails to adequately sanitize or authorize.\nThe scope change (S:C) indicates that the vulnerability allows the attacker to break out of the intended boundaries of the Project Discovery component. This suggests an injection or escalation flaw where the input processing logic permits the manipulation of underlying system commands or server-side resources that interact with other Oracle PeopleSoft modules or the underlying host operating system.\nOnce the initial request is processed, the payload is executed within the application's runtime environment. Given the high impact on confidentiality, integrity, and availability (C:H/I:H/A:H), the exploitation results in the attacker gaining elevated control over the component. This often involves bypassing access control lists (ACLs) or manipulating application state to execute unauthorized arbitrary code or access restricted data stores.\nPost-exploitation, the attacker possesses the capability to modify project configurations, exfiltrate sensitive in-memory data, or interfere with system availability. Because the vulnerability affects the In-Memory component, the impact can be immediate and widespread across the enterprise deployment, as these components often hold volatile, mission-critical data that influences downstream processes. The lack of requirement for user interaction (UI:N) ensures that the exploit can be scripted and executed efficiently by an adversary, further increasing the risk of successful compromise in production environments."
}
CVE-2026-61209: PeopleSoft Project Discovery Critical Takeover (CRITICAL Severity, CVSS: 9.9) - Sceawere