SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61201 2026-07-21

CVE-2026-61201: Critical PeopleSoft CRM Flaw Allows Unauthenticated Takeover

"Oracle has disclosed CVE-2026-61201, a critical (CVSS 9.0) vulnerability in PeopleSoft Enterprise CRM Common Objects that lets an unauthenticated attacker take over the affected component over the network."

Oracle has disclosed CVE-2026-61201, a critical (CVSS 9.0) vulnerability in PeopleSoft Enterprise CRM Common Objects that lets an unauthenticated attacker take over the affected component over the network.

What Is It

CVE-2026-61201 is a vulnerability in the Common Objects component of Oracle PeopleSoft's Enterprise CRM Common Objects product. According to Oracle, the flaw is difficult to exploit but allows an unauthenticated attacker with network access via HTTP to compromise the product. Although the vulnerability itself resides in PeopleSoft Enterprise CRM Common Objects, a scope change means attacks may significantly impact additional products. Successful exploitation can result in full takeover of the affected component.

Why It Matters

The vulnerability carries a CVSS 3.1 base score of 9.0 (CRITICAL), with the vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H. It requires no privileges and no user interaction, and it can be reached over the network. Successful attacks yield high impact to confidentiality, integrity, and availability, and the changed scope (S:C) means the damage can extend beyond the vulnerable component to other products. The only mitigating factor is high attack complexity (AC:H), which Oracle characterizes as making the flaw difficult to exploit.

What's Vulnerable

Patch Status

The CVE is referenced in Oracle's Critical Patch Update advisory for July 2026 (cpujul2026.html), indicating the fix is addressed in that release. Organizations running PeopleSoft Enterprise CRM Common Objects 9.2.23 should apply the July 2026 Critical Patch Update. This CVE does not appear in the CISA Known Exploited Vulnerabilities catalog based on the supplied data, and no confirmation of active exploitation is available.

Sources