SYS::ONLINE
Wasteland.
Briefs1482
Issues20
SinceFeb 2026
LIVE
⚡ Active KEV CVE-2026-61204 2026-07-21

CVE-2026-61204: Critical PeopleSoft FIN Program Management Takeover Flaw

"A critical (CVSS 9.0) vulnerability in Oracle PeopleSoft Enterprise FIN Program Management allows a low-privileged, network-based attacker to take over the product and impact additional systems through a scope change."

A critical (CVSS 9.0) vulnerability in Oracle PeopleSoft Enterprise FIN Program Management allows a low-privileged, network-based attacker to take over the product and impact additional systems through a scope change.

What Is It

CVE-2026-61204 is a critical vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft, specifically in the Primavera Integration component. Oracle describes it as an easily exploitable flaw that lets a low-privileged attacker with network access via HTTP compromise the product. Successful attacks require human interaction from a person other than the attacker. Because the vulnerability carries a scope change, a successful exploit may significantly impact additional products beyond the initial target. Oracle assigns it a CVSS 3.1 base score of 9.0 with the vector AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H, reflecting high confidentiality, integrity, and availability impacts.

Why It Matters

A successful attack can result in full takeover of PeopleSoft Enterprise FIN Program Management. The scope change means the blast radius is not confined to the vulnerable component; adjacent products may be significantly affected. With low attack complexity and only low privileges required, the barrier to exploitation is modest; the sole mitigating factor is the requirement for human interaction. PeopleSoft systems commonly hold sensitive financial and program management data, making a takeover consequential for affected organizations.

What's Vulnerable

Patch Status

This CVE was published as part of Oracle's July 2026 Critical Patch Update. Organizations running the affected version should consult Oracle's Critical Patch Update advisory and apply the corresponding fixes. There is no CISA KEV entry supplied for this CVE, so active exploitation is not confirmed in the provided source material.

Sources