Description
Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery. While the vulnerability is in PeopleSoft In-Memory Project Discovery, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft In-Memory Project Discovery. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Oracle PeopleSoft In-Memory Project Discovery version 9.2 can be exploited by a low‑privileged attacker who has network access via HTTP. The flaw permits bypassing privilege checks and effectively taking control of the affected service, corresponding to CWE‑269: Improper Privilege Management. Successful exploitation results in full compromise of confidentiality, integrity, and availability for that instance. Because the vulnerability’s scope changes, the impact extends beyond the In‑Memory Project Discovery component and may affect additional PeopleSoft products as well.

Affected Systems

Oracle PeopleSoft In-Memory Project Discovery version 9.2, part of Oracle PeopleSoft. Although the vulnerability is specific to that component, the scope change indicates that other PeopleSoft products may also be impacted by exploitation.

Risk and Exploitability

The CVSS v3.1 base score of 9.9 indicates a critical severity level. The EPSS score of less than 1 % suggests that, as of the latest data, exploitation is unlikely to be widespread. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploit has been reported. Attackers can reach the vulnerable component via standard HTTP requests, requiring only a low‑privileged account. The scope change means that exploitation could affect more than the targeted component, potentially impacting other PeopleSoft products. The combination of remote access, low attack effort, and this expanded impact makes the flaw a high‑priority risk.

Generated by OpenCVE AI on August 4, 2026 at 01:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the Oracle PeopleSoft In-Memory Project Discovery patch released in the July 2026 CPU alert.
  • Restrict external HTTP access to the service using firewalls or network segmentation until the patch is applied.
  • Monitor logs for anomalous authentication attempts and unusual activity on the project discovery service to detect potential exploitation.

Generated by OpenCVE AI on August 4, 2026 at 01:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Vulnerability in Oracle PeopleSoft In-Memory Project Discovery via HTTP

Thu, 30 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation Vulnerability in Oracle PeopleSoft In-Memory Project Discovery via HTTP

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Full Takeover of Oracle PeopleSoft In-Memory Project Discovery 9.2

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Low‑Privilege HTTP Exploit Enables Full Takeover of Oracle PeopleSoft In-Memory Project Discovery 9.2

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery. While the vulnerability is in PeopleSoft In-Memory Project Discovery, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft In-Memory Project Discovery. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle peoplesoft In-memory Project Discovery
CPEs cpe:2.3:a:oracle:peoplesoft_in-memory_project_discovery:9.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle peoplesoft In-memory Project Discovery
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Oracle Peoplesoft In-memory Project Discovery
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-22T18:25:58.899Z

Reserved: 2026-07-08T15:52:20.741Z

Link: CVE-2026-61209

cve-icon Vulnrichment

Updated: 2026-07-22T18:25:54.298Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T01:30:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management