SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61076 2026-07-21

Oracle PeopleSoft HCM Talent Acquisition Manager Critical Takeover Flaw (CVE-2026-61076)

"A critical, easily exploitable flaw in Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager 9.2 lets a low-privileged network attacker fully take over the application, with impact spreading beyond it."

A critical, easily exploitable flaw in Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager 9.2 lets a low-privileged network attacker fully take over the application, with impact spreading beyond it.

What Is It

CVE-2026-61076 is a vulnerability in the Job Opening component of Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager. Oracle describes it as easily exploitable, allowing a low-privileged attacker with network access over HTTP to compromise the product. Notably, the vulnerability carries a scope change: while the flaw lives in Talent Acquisition Manager, successful attacks may significantly impact additional products beyond the vulnerable component. Successful exploitation can result in complete takeover of the affected application.

Why It Matters

The vulnerability holds a CVSS 3.1 base score of 9.9 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. That combination, network attack vector, low attack complexity, only low privileges required, and no user interaction, means an authenticated but low-level user can reach it remotely with little effort. The scope change plus high Confidentiality, Integrity, and Availability impacts make this a full-takeover scenario that can cascade to other products. HR and recruiting platforms hold sensitive personal and organizational data, raising the stakes of a compromise.

Note: the supplied CISA KEV entry is empty, so there is no confirmation of active exploitation in this source material.

What's Vulnerable

Patch Status

The vulnerability was published July 21, 2026, with a Received status in NVD. Oracle addressed it in the July 2026 Critical Patch Update. Organizations running PeopleSoft HCM Talent Acquisition Manager 9.2 should apply the fixes referenced in Oracle's Critical Patch Update Advisory without delay, given the critical score and low exploitation barrier.

Sources