Description
Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CRM Common Objects. While the vulnerability is in PeopleSoft Enterprise CRM Common Objects, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CRM Common Objects. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in PeopleSoft Enterprise CRM Common Objects allows an unauthenticated attacker with network access over HTTP to take full control of the application, resulting in confidentiality, integrity, and availability compromise. The weakness is a failure in authorization and privilege handling as indicated by the Scope Change in the CVSS vector, which enables system takeover. The impact is a complete loss of the affected instance for the adversary.

Affected Systems

Oracle Corporation PeopleSoft Enterprise CRM Common Objects, version 9.2.23. The advisory applies specifically to this product version; no other versions are listed as affected.

Risk and Exploitability

The CVSS score of 9.0 classifies this as Critical, with a high impact on all three security objectives. The EPSS score of <1% suggests low overall exploitation probability, and the vulnerability is not currently listed in the CISA KEV catalog. However, the vulnerability may be leveraged remotely over an open HTTP interface without authentication, making it potentially attractive to attackers that can reach the network. The Scope Change in the CVSS vector indicates that successful exploitation could extend to additional PeopleSoft products beyond the Common Objects component. The weakness permits privilege escalation and full takeover of the application environment.

Generated by OpenCVE AI on August 4, 2026 at 01:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle PeopleSoft security patch released in the CPU Jul 2026 advisory, which addresses the unauthenticated HTTP exploitation in Common Objects.
  • Restrict HTTP access to the PeopleSoft application by applying network segmentation, firewalls, or web‑application gateway rules so that only trusted systems can reach the exposed endpoints.
  • Monitor inbound HTTP traffic for anomalous activity or repeated failed requests that may indicate probing for the known exploit path.

Generated by OpenCVE AI on August 4, 2026 at 01:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in PeopleSoft CRM Common Objects

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Remote Code Execution in PeopleSoft CRM Common Objects

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Enables System Takeover in PeopleSoft 9.2.23
Weaknesses CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Unauthenticated HTTP Exploit Enables System Takeover in PeopleSoft 9.2.23
Weaknesses CWE-269
CWE-284
CWE-285
CWE-306
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise CRM Common Objects product of Oracle PeopleSoft (component: Common Objects). The supported version that is affected is 9.2.23. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CRM Common Objects. While the vulnerability is in PeopleSoft Enterprise CRM Common Objects, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CRM Common Objects. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Crm Common Objects
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_crm_common_objects:9.2.23:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Crm Common Objects
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Crm Common Objects
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-30T03:55:37.439Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61201

cve-icon Vulnrichment

Updated: 2026-07-22T19:25:31.959Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-306

    Missing Authentication for Critical Function