Sceawere
Vulnerability Detail
CVE-2026-61242Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft Staffing Component RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Common Objects Argentina
- Attack Type
- Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Argentina.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-07-21T22:18:55.010Z",
"pubdate": "2026-07-21T22:18:55.010Z",
"executiveSummary": "This vulnerability affects the Staffing component within the PeopleSoft Enterprise FIN Common Objects Argentina product, specifically version 9.1.\nThe flaw allows a low-privileged, remote attacker to gain full unauthorized control over the affected system via the HTTP protocol.\nCategorized as a critical security risk with a CVSS 3.1 base score of 9.9, this vulnerability exhibits a significant scope change, meaning exploitation may facilitate lateral movement or compromise of adjacent systems beyond the immediate application.\nThe vulnerability provides the attacker with full Confidentiality, Integrity, and Availability (C) impact, effectively resulting in a complete takeover of the affected product.\nBecause the vulnerability is easily exploitable with low privileges and no user interaction, the risk to the enterprise is extreme, requiring immediate attention to mitigate unauthorized access and data exfiltration.",
"technicalDetails": "The vulnerability resides within the Staffing component of PeopleSoft Enterprise FIN Common Objects Argentina version 9.1. It is classified as an easily exploitable flaw that does not require user interaction, leveraging a network-based attack vector via HTTP.\nThe technical root cause involves inadequate security controls within the Staffing component, which fails to properly sanitize or authorize inputs or operations requested by low-privileged users. By sending specifically crafted HTTP requests, an attacker can bypass existing authentication and authorization mechanisms to execute arbitrary code or commands within the application's process context.\nThe attack flow initiates when an authenticated low-privileged attacker transmits a malicious HTTP request to the Staffing component. Due to the lack of sufficient validation or restriction on the server-side, the input triggers an unexpected execution path. Given the architectural scope change (S:C), the compromise of this component extends the attacker's influence beyond the immediate PeopleSoft environment, potentially granting them escalated system-level privileges.\nSuccessful exploitation results in full administrative control over the targeted application. Once the attacker achieves remote code execution, they can perform unauthorized actions, including the extraction of sensitive business data, the modification of financial records, or the destruction of system availability (denial-of-service).\nBecause the CVSS vector identifies the vulnerability as AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, it is evident that the vulnerability exists within an interface that is reachable over the network. The low complexity (AC:L) ensures that the barrier to entry for an attacker is minimal. The integrity and confidentiality of the entire PeopleSoft ecosystem are compromised because the vulnerability permits the attacker to bypass the security boundary of the FIN Common Objects Argentina module to interact with other dependent or interconnected resources."
}