Sceawere

Vulnerability Detail

CVE-2026-61235Updated Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft Global Payroll Unauthorized Takeover

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
4h ago
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise HCM Global Payroll Switzerland
Attack Type
Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Switzerland. While the vulnerability is in PeopleSoft Enterprise HCM Global Payroll Switzerland, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Global Payroll Switzerland.
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Switzerland product of Oracle PeopleSoft (component: Global Payroll for Switzerland). The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Switzerland. While the vulnerability is in PeopleSoft Enterprise HCM Global Payroll Switzerland, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Global Payroll Switzerland. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-07-21T22:18:54.357Z",
  "pubdate": "2026-07-21T22:18:54.357Z",
  "executiveSummary": "This vulnerability affects the Global Payroll for Switzerland component within Oracle PeopleSoft Enterprise HCM version 9.2. It represents a critical security flaw allowing a highly privileged attacker to achieve full system compromise.\nThe vulnerability is characterized by a scope-changing capability, meaning an attacker can move beyond the Global Payroll component to impact the broader PeopleSoft environment or integrated systems. Due to the high-privilege requirement, this exploit leverages existing administrative access to escalate or execute arbitrary commands at the system level.\nThe risk is classified as critical, with a CVSS 3.1 base score of 9.1, reflecting the complete loss of confidentiality, integrity, and availability. Attackers require network access via HTTP, making the application reachable if exposed to a network. Successful exploitation leads to total control over the affected component, potentially compromising data across the entire HCM suite.",
  "technicalDetails": "The vulnerability resides within the Global Payroll for Switzerland component of PeopleSoft Enterprise HCM 9.2. It functions as a critical weakness in input validation or command execution handling within the application's administrative interface. Despite the requirement for high-level privileges, the ability to trigger a scope change (S:C) indicates that the vulnerability allows an attacker to bypass security boundaries established between the component and the underlying application server or integrated modules.\nThe attack flow begins with the adversary authenticated to the PeopleSoft environment with high-privileged credentials. Leveraging the network accessibility of the Global Payroll component, the attacker sends a specially crafted HTTP request designed to exploit the underlying flaw. Because the vulnerability allows for a scope change, the execution context is not restricted to the Global Payroll module; the payload can interact with the PeopleSoft application server in a way that violates system integrity. This potentially permits the execution of unauthorized functions or the manipulation of system files.\nThe root cause is likely an insecure handling of administrative operations or improper validation of inputs that are passed to sensitive backend processes. When these inputs are processed by the Global Payroll component, they facilitate a breakout scenario. Since the vulnerability is remotely exploitable via HTTP (AV:N), it poses a significant threat to environments where administrative interfaces are accessible over the network. The low attack complexity (AC:L) suggests that once the privilege requirement is met, the exploit path is straightforward, requiring no user interaction (UI:N).\nPost-exploitation, the attacker gains full control over the PeopleSoft Enterprise HCM Global Payroll Switzerland component. Given the nature of the scope change, the impact extends to the confidentiality, integrity, and availability of data managed by the HCM suite. An attacker could exfiltrate sensitive payroll data, modify payroll configurations, or disrupt business continuity by rendering the application unavailable. Furthermore, the escalation may allow for lateral movement within the enterprise architecture, potentially exposing other connected Oracle infrastructure components to further exploitation."
}
CVE-2026-61235: PeopleSoft Global Payroll Unauthorized Takeover (CRITICAL Severity, CVSS: 9.1) - Sceawere