Description
Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent Acquisition Manager. While the vulnerability is in PeopleSoft Enterprise HCM Talent Acquisition Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Talent Acquisition Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Job Opening component of Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager version 9.2. An attacker who is only logged in with low privileges and has network access through HTTP can exploit this flaw. The flaw is easily exploitable and, if successful, allows the attacker to compromise the entire application, abolishing confidentiality, integrity and availability. The CVSS vector lists an Attack Vector of Network, Authentication required is low, and the scope is of a low‑privileged user can lead to full takeover of the system.

Affected Systems

The affected vendor is Oracle Corporation, product PeopleSoft Enterprise HCM Talent Acquisition Manager. The only explicitly impacted release is version 9.2. No other products or versions are mentioned; however, the description states that the issue may have a broader scope that could affect additional PeopleSoft products.

Risk and Exploitability

The CVSS base score is 9.9, the maximum severity. The EPSS score indicates a very low current exploitation probability (< 1 %), and the vulnerability is not currently listed in CISA’s KEV catalog. Nevertheless, because the attack can be initiated from a network node using HTTP the risk of compromise remains high once the flaw exists. If left unpatched, an adversary could gain unrestricted access to the application, enabling data exfiltration, modification, and denial of service.

Generated by OpenCVE AI on August 4, 2026 at 01:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle patch released in the July 2026 Critical Patch Update for PeopleSoft Enterprise HCM Talent Acquisition Manager
  • Restrict inbound HTTP access to the PeopleSoft instance by configuring firewalls or VPN controls so that only trusted internal networks can reach the Job Opening component
  • Deploy monitoring and logging to detect anomalous activity on the Job Opening interface, and enforce network segmentation so that the application cannot be accessed directly from untrusted segments

Generated by OpenCVE AI on August 4, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
Title PeopleSoft Talent Acquisition Manager 9.2 Low-Privilege HTTP Exploit Enables Full System Takeover

Tue, 28 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Low-Privilege HTTP Attack in PeopleSoft Enterprise HCM Talent Acquisition Manager
Weaknesses CWE-264
CWE-285

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Low-Privilege HTTP Attack in PeopleSoft Enterprise HCM Talent Acquisition Manager
Weaknesses CWE-264
CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise HCM Talent Acquisition Manager product of Oracle PeopleSoft (component: Job Opening). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Talent Acquisition Manager. While the vulnerability is in PeopleSoft Enterprise HCM Talent Acquisition Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise HCM Talent Acquisition Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Hcm Talent Acquisition Manager
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_hcm_talent_acquisition_manager:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Hcm Talent Acquisition Manager
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Hcm Talent Acquisition Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:00:32.016Z

Reserved: 2026-07-08T15:51:55.611Z

Link: CVE-2026-61076

cve-icon Vulnrichment

Updated: 2026-07-24T14:00:26.621Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:38.410

Modified: 2026-08-06T15:02:33.810

Link: CVE-2026-61076

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:00:12Z

Weaknesses
  • CWE-269

    Improper Privilege Management