Sceawere
Vulnerability Detail
CVE-2026-61237Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft Integration Unauthenticated Remote Compromise
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Common Objects Argentina
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise FIN Common Objects Argentina accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Common Objects Argentina accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:L).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-07-21T22:18:54.573Z",
"pubdate": "2026-07-21T22:18:54.573Z",
"executiveSummary": "A critical security vulnerability exists within the Integration component of Oracle PeopleSoft Enterprise FIN Common Objects Argentina version 9.1.\nThis vulnerability is classified as remotely exploitable, allowing an unauthenticated attacker to achieve unauthorized access to the application environment.\nThe flaw carries a CVSS 3.1 base score of 9.9, reflecting its high impact on Confidentiality, Integrity, and Availability.\nThe scope change attribute indicates that successful exploitation can lead to a compromise extending beyond the immediate product to encompass additional integrated systems.\nAttackers can leverage network access via the HTTP protocol to execute unauthorized data operations, including unauthorized reading, modification, or deletion of critical information.\nThe potential for partial denial of service (DoS) further exacerbates the risk to system availability.\nDue to the lack of required authentication and the low complexity of the attack vector, this vulnerability poses a severe risk to organizations utilizing the affected version, necessitating immediate remediation efforts.",
"technicalDetails": "The vulnerability resides within the Integration component of PeopleSoft Enterprise FIN Common Objects Argentina version 9.1. It facilitates a high-severity security breach by enabling unauthenticated actors to interact with internal business logic via the HTTP protocol.\nThe root cause involves improper input validation or insufficient access control mechanisms within the Integration component, which fails to verify the authenticity or authorization of incoming network requests. By leveraging these weaknesses, an attacker can bypass standard security barriers to influence the application's internal processes.\nThe attack flow begins with the adversary targeting the network-exposed HTTP endpoint associated with the PeopleSoft Integration component. Since the vulnerability allows unauthenticated access, the attacker does not require valid credentials or prior session tokens to initiate the request. By crafting specialized HTTP requests, the attacker can manipulate the integration interfaces to interact with underlying backend functionalities.\nThe scope of the impact is critical; the 'Scope Changed' (S:C) metric indicates that the vulnerability provides an entry point for an attacker to pivot or escalate privileges into connected systems or broader infrastructure associated with the PeopleSoft environment. This suggests that the trust boundary of the Integration component is insufficient to protect the wider ecosystem.\nSuccessful exploitation results in significant impacts across the CIA triad. Regarding Confidentiality, the attacker gains the ability to exfiltrate critical, sensitive data hosted within the application. In terms of Integrity, the attacker is granted unauthorized read/write access, allowing for the unauthorized insertion, modification, or deletion of sensitive records. Regarding Availability, the attacker can trigger conditions that lead to a partial denial of service, effectively degrading the application's operational capacity.\nBecause the attack vector is network-based (AV:N) and requires low attack complexity (AC:L) with no privileges (PR:N) and no user interaction (UI:N), the vulnerability can be exploited programmatically using automated tools, making it an attractive target for malicious actors seeking to compromise organizational databases and internal workflows. The technical manifestation of the exploit involves direct HTTP interactions that exploit the vulnerable integration functions, potentially bypassing secondary defenses if those defenses rely solely on the inherent, yet absent, security controls of the Integration component."
}