Description
Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Program Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Program Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Program Management. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in the Primavera Integration component of Oracle PeopleSoft Enterprise FIN Program Management version 9.2. An attacker possessing a low‑privileged network account that can reach the application over HTTP can exploit the vulnerability after a different user performs a single interaction. The successful exploit allows the attacker to gain unrestricted control of the PeopleSoft instance, exposing sensitive data, compromising data integrity, and rendering the application unavailable. This results in a full system compromise with complete confidentiality, integrity and availability impact.

Affected Systems

Oracle PeopleSoft Enterprise FIN Program Management version 9.2 is the only product explicitly listed as affected by the CNA. The advisory does not indicate any other Oracle products are impacted.

Risk and Exploitability

The CVSS 3.1 score of 9.0 classifies the vulnerability as critical, and the EPSS score of less than 1 % indicates that exploitation incidents are currently rare. The vulnerability is not listed in CISA KEV. Exploitation requires network reachability to the application over HTTP, a low‑privileged account, and a prior user interaction to trigger the flaw. Once triggered, the attacker can assume full control of the PeopleSoft environment, covering all confidentiality, integrity, and availability concerns. The associated weaknesses are CWE‑269 (Broken or Incorrect Authentication), CWE‑284 (Improper Authorization) and CWE‑352 (Cross‑Site Request Forgery).

Generated by OpenCVE AI on August 5, 2026 at 01:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch for CVE‑2026‑61204 as soon as it becomes available.
  • Restrict HTTP access to the PeopleSoft server to trusted IP ranges or require VPN connectivity to limit reachability.
  • If the Primavera Integration component is not required for business operations, disable or uninstall it to remove the attack surface.
  • Enforce multi‑factor authentication for all user accounts and apply strict access controls for low‑privileged users.
  • Configure Web Application Firewall rules to detect and block CSRF attempts and monitor logs for suspicious activity.

Generated by OpenCVE AI on August 5, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Primavera Integration Low-Privilege Exploit Allows Full System Compromise in PeopleSoft Enterprise FIN Program Management

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Primavera Integration Low-Privilege Exploit Allows Full System Compromise in PeopleSoft Enterprise FIN Program Management

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Primavera Integration Vulnerability Allows Full System Compromise via Low-Privilege HTTP Access

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Primavera Integration Vulnerability Allows Full System Compromise via Low-Privilege HTTP Access

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
CWE-284
CWE-352
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft Enterprise FIN Program Management product of Oracle PeopleSoft (component: Primavera Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Program Management. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise FIN Program Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Program Management. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft Enterprise Fin Program Management
CPEs cpe:2.3:a:oracle:peoplesoft_enterprise_fin_program_management:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft Enterprise Fin Program Management
References
Metrics cvssV3_1

{'score': 9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft Enterprise Fin Program Management
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T19:27:15.837Z

Reserved: 2026-07-08T15:52:20.740Z

Link: CVE-2026-61204

cve-icon Vulnrichment

Updated: 2026-07-22T19:27:12.193Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-284

    Improper Access Control

  • CWE-352

    Cross-Site Request Forgery (CSRF)