A critical (CVSS 9.9) vulnerability in Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil lets a low-privileged, network-based attacker fully take over the product and impact adjacent systems.
What Is It
CVE-2026-61072 is a vulnerability in the Staffing component of Oracle PeopleSoft Enterprise FIN Staffing Front Office Brazil. According to Oracle's advisory, it is easily exploitable: a low-privileged attacker with network access over HTTP can compromise the product without any user interaction. The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, yielding a base score of 9.9 (CRITICAL) with high impact to confidentiality, integrity, and availability.
Why It Matters
The flaw carries a scope change (S:C), meaning that although the vulnerability resides in the Staffing Front Office Brazil product, successful attacks "may significantly impact additional products" beyond the initial vulnerable component. Oracle states that successful exploitation can result in complete takeover of the affected product. The combination of network reachability, low attack complexity, only low privileges required, and no user interaction makes this an attractive target once exploit details circulate.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: PeopleSoft Enterprise FIN Staffing Front Office Brazil
- Component: Staffing
- Affected version: 9.1
Patch Status
The vulnerability was disclosed by Oracle (source identifier [email protected]) and is addressed in the Oracle Critical Patch Update for July 2026. Administrators running PeopleSoft Enterprise FIN Staffing Front Office Brazil 9.1 should apply the fixes referenced in that Critical Patch Update advisory. As of this record, the NVD status is "Received" and no CISA KEV entry was supplied, so there is no confirmation of active exploitation in the provided source material.