A critical (CVSS 9.0) vulnerability in Oracle PeopleSoft Enterprise FIN Program Management allows a low-privileged, network-based attacker to take over the product and impact additional systems through a scope change.
What Is It
CVE-2026-61204 is a critical vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft, specifically in the Primavera Integration component. Oracle describes it as an easily exploitable flaw that lets a low-privileged attacker with network access via HTTP compromise the product. Successful attacks require human interaction from a person other than the attacker. Because the vulnerability carries a scope change, a successful exploit may significantly impact additional products beyond the initial target. Oracle assigns it a CVSS 3.1 base score of 9.0 with the vector AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H, reflecting high confidentiality, integrity, and availability impacts.
Why It Matters
A successful attack can result in full takeover of PeopleSoft Enterprise FIN Program Management. The scope change means the blast radius is not confined to the vulnerable component; adjacent products may be significantly affected. With low attack complexity and only low privileges required, the barrier to exploitation is modest; the sole mitigating factor is the requirement for human interaction. PeopleSoft systems commonly hold sensitive financial and program management data, making a takeover consequential for affected organizations.
What's Vulnerable
- Vendor: Oracle Corporation
- Product: PeopleSoft Enterprise FIN Program Management
- Component: Primavera Integration
- Affected version: 9.2
Patch Status
This CVE was published as part of Oracle's July 2026 Critical Patch Update. Organizations running the affected version should consult Oracle's Critical Patch Update advisory and apply the corresponding fixes. There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the provided source material.