Sceawere

Vulnerability Detail

CVE-2026-61237Updated Verified Sceawere Triage Sources: NVD / CISA KEV

PeopleSoft Integration Unauthenticated Remote Compromise

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.9
Creation Date
4h ago
Vendor
Oracle Corporation
Product
PeopleSoft Enterprise FIN Common Objects Argentina
Attack Type
Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina.
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L).

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.9",
  "pubDate": "2026-07-21T22:18:54.573Z",
  "pubdate": "2026-07-21T22:18:54.573Z",
  "executiveSummary": "A critical security vulnerability exists within the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina version 9.1.\nThis vulnerability is classified as remotely exploitable, allowing an unauthenticated attacker to achieve unauthorized access to the application environment.\nThe flaw carries a CVSS 3.1 base score of 9.9, reflecting its high impact on Confidentiality, Integrity, and Availability.\nThe scope change attribute indicates that successful exploitation can lead to a compromise extending beyond the immediate product to encompass additional integrated systems.\nAttackers can leverage network access via the HTTP protocol to execute unauthorized data operations, including unauthorized reading, modification, or deletion of critical information.\nThe potential for partial denial of service (DoS) further exacerbates the risk to system availability.\nDue to the lack of required authentication and the low complexity of the attack vector, this vulnerability poses a severe risk to organizations utilizing the affected version, necessitating immediate remediation efforts.",
  "technicalDetails": "The vulnerability resides within the Integration component of PeopleSoft Enterprise FIN Common Objects Argentina version 9.1. It facilitates a high-severity security breach by enabling unauthenticated actors to interact with internal business logic via the HTTP protocol.\nThe root cause involves improper input validation or insufficient access control mechanisms within the Integration component, which fails to verify the authenticity or authorization of incoming network requests. By leveraging these weaknesses, an attacker can bypass standard security barriers to influence the application's internal processes.\nThe attack flow begins with the adversary targeting the network-exposed HTTP endpoint associated with the PeopleSoft Integration component. Since the vulnerability allows unauthenticated access, the attacker does not require valid credentials or prior session tokens to initiate the request. By crafting specialized HTTP requests, the attacker can manipulate the integration interfaces to interact with underlying backend functionalities.\nThe scope of the impact is critical; the 'Scope Changed' (S:C) metric indicates that the vulnerability provides an entry point for an attacker to pivot or escalate privileges into connected systems or broader infrastructure associated with the PeopleSoft environment. This suggests that the trust boundary of the Integration component is insufficient to protect the wider ecosystem.\nSuccessful exploitation results in significant impacts across the CIA triad. Regarding Confidentiality, the attacker gains the ability to exfiltrate critical, sensitive data hosted within the application. In terms of Integrity, the attacker is granted unauthorized read/write access, allowing for the unauthorized insertion, modification, or deletion of sensitive records. Regarding Availability, the attacker can trigger conditions that lead to a partial denial of service, effectively degrading the application's operational capacity.\nBecause the attack vector is network-based (AV:N) and requires low attack complexity (AC:L) with no privileges (PR:N) and no user interaction (UI:N), the vulnerability can be exploited programmatically using automated tools, making it an attractive target for malicious actors seeking to compromise organizational databases and internal workflows. The technical manifestation of the exploit involves direct HTTP interactions that exploit the vulnerable integration functions, potentially bypassing secondary defenses if those defenses rely solely on the inherent, yet absent, security controls of the Integration component."
}
CVE-2026-61237: PeopleSoft Integration Unauthenticated Remote Compromise (CRITICAL Severity, CVSS: 9.9) - Sceawere