Sceawere

Vulnerability Detail

CVE-2026-61233Updated Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft Integration Remote Compromise

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Common Objects Brazil
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-07-21T22:18:54.133Z",
  "pubdate": "2026-07-21T22:18:54.133Z",
  "executiveSummary": "This vulnerability affects the Oracle PeopleSoft Enterprise FIN Common Objects Brazil product, specifically within the Integration component. It is classified as a critical remote code execution or system takeover vulnerability due to its high CVSS 3.1 base score of 9.8.\nThe vulnerability allows an unauthenticated attacker to gain unauthorized access to the system via the network using the HTTP protocol. By exploiting weaknesses in the Integration component, a remote actor can successfully compromise the integrity, confidentiality, and availability of the affected PeopleSoft environment.\nThe lack of authentication requirements and the ability to leverage network access facilitate a high-risk scenario where an attacker can execute arbitrary commands or manipulate data without requiring prior system interaction or elevated privileges. Organizations utilizing version 9.1 are at significant risk of total system takeover, which could lead to unauthorized data exfiltration, service disruption, and complete administrative control over the application environment.\nGiven the nature of the exploit, it is considered easily exploitable with a low attack complexity, requiring no user interaction. Immediate defensive measures are required to secure the Integration interface and mitigate the potential for unauthorized system compromise.",
  "technicalDetails": "The vulnerability is situated within the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Brazil, specifically impacting version 9.1. The flaw manifests in how the component processes incoming HTTP requests, failing to implement adequate authentication controls or input validation mechanisms. This lack of verification allows remote, unauthenticated actors to interact with sensitive integration functions that are otherwise intended to be protected.\nThe exploitation process involves sending specially crafted HTTP requests to the target Integration component. Because the component does not validate the identity of the requester, it processes the payload as a legitimate administrative or system-level command. The network exposure is broad, as the HTTP-based interface is reachable across the network, making it a prime vector for exploitation.\nUpon successful transmission of the malicious payload, the Integration component executes the unauthorized operation. The internal architecture of PeopleSoft Enterprise FIN Common Objects Brazil in this version does not enforce sufficient boundary checks between the network-facing Integration interface and the underlying application logic. This allows an attacker to manipulate the state of the application, potentially leading to the execution of system-level functions.\nThe attack flow proceeds as follows: First, the attacker identifies the reachable HTTP endpoint associated with the PeopleSoft Integration component. Second, the attacker probes the interface to determine the expected format for integration objects. Third, the attacker transmits a malicious payload designed to bypass existing security logic. Finally, the application executes the malicious commands or data modifications as if they originated from an authorized internal source, resulting in a full system compromise. The impact of such an exploit is total, as the attacker gains the ability to intercept sensitive financial data, modify database records, or terminate application processes, effectively assuming full control over the PeopleSoft instance. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) confirms that the vulnerability is remotely exploitable without privileges or user interaction, with impacts spanning across the entire CIA triad."
}
CVE-2026-61233: PeopleSoft Integration Remote Compromise (CRITICAL Severity, CVSS: 9.8) - Sceawere