Sceawere
Vulnerability Detail
CVE-2026-61245Updated Verified Sceawere Triage Sources: NVD / CISA KEV
PeopleSoft Unauthenticated Remote Takeover
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.8
- Creation Date
- 4h ago
- Vendor
- Oracle Corporation
- Product
- PeopleSoft Enterprise FIN Manufacturing Brazil
- Attack Type
- Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise FIN Manufacturing Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Manufacturing Brazil.
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Vulnerability in the PeopleSoft Enterprise FIN Manufacturing Brazil product of Oracle PeopleSoft (component: Integration). The supported version that is affected is 9.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise FIN Manufacturing Brazil. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Manufacturing Brazil. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.8",
"pubDate": "2026-07-21T22:18:55.343Z",
"pubdate": "2026-07-21T22:18:55.343Z",
"executiveSummary": "A critical security vulnerability exists within the Integration component of Oracle PeopleSoft Enterprise FIN Manufacturing Brazil version 9.1.\nThis vulnerability is classified as a high-severity flaw allowing for total system compromise by an unauthenticated attacker with network access via HTTPS.\nThe vulnerability carries a CVSS 3.1 Base Score of 9.8, indicating maximum impact on Confidentiality, Integrity, and Availability (CIA).\nThe attack vector is network-based (AV:N) and requires low attack complexity (AC:L) with no required privileges (PR:N) or user interaction (UI:N).\nGiven that the vulnerability allows for complete takeover, the risk to the organization is catastrophic, potentially leading to unauthorized data access, modification of financial records, and denial of service.\nImmediate attention is required to secure the affected integration interfaces against unauthorized remote exploitation.",
"technicalDetails": "The vulnerability resides in the Integration component of Oracle PeopleSoft Enterprise FIN Manufacturing Brazil version 9.1, specifically affecting how the application processes inbound requests over HTTPS.\nThe root cause of this vulnerability lies in improper validation of incoming requests or inadequate authentication enforcement within the integration framework. This flaw allows a remote, unauthenticated attacker to inject or bypass security controls intended to guard internal application functions.\nAttackers can leverage this vulnerability by crafting malicious packets sent over HTTPS to the vulnerable integration endpoint. Because the application fails to perform sufficient authentication or authorization checks before processing these requests, the attacker can execute arbitrary commands or manipulate application logic.\nThe attack flow proceeds as follows: First, the attacker identifies the exposed integration endpoint accessible over the network. Second, the attacker crafts a payload that circumvents the application's expected authentication mechanisms. Third, the payload is transmitted via HTTPS to the Integration component. Finally, the server processes the malicious request with elevated privileges, leading to the execution of unintended functions.\nThe impact of a successful exploitation is a complete takeover of the PeopleSoft Enterprise FIN Manufacturing Brazil product. This allows the attacker to gain full administrative control, which may include the unauthorized exfiltration of sensitive financial data, the modification of production manufacturing records, and the total disruption of business operations through service degradation or system shutdown.\nSince the vulnerability exists within the Integration layer, it is likely that the flaw stems from a lack of secure session management or improper sanitization of inputs within the communication interface used for cross-system data exchange. The scope of the vulnerability is unchanged (S:U), meaning the impact is contained within the PeopleSoft application layer, yet the severity remains critical due to the ease of exploitation and the lack of required authentication. No specific user interaction is required, making the attack highly automated and easily scalable once the vulnerable endpoint is discovered by an adversary."
}