CVE-2026-61072
Oracle · PeopleSoft Enterprise FIN Staffing Front Office Brazil
A critical flaw in PeopleSoft Enterprise FIN Staffing Front Office Brazil allows a low-privileged, network-based attacker to achieve full system takeover via HTTP.
Executive summary
A critical security vulnerability in PeopleSoft Enterprise FIN Staffing Front Office Brazil allows an authenticated attacker to gain full control of the system, requiring immediate remediation.
Vulnerability
The vulnerability, located in the Staffing component, allows a low-privileged attacker to compromise the system over a network via HTTP. A scope change exists, meaning the vulnerability can impact other products within the PeopleSoft environment, leading to a complete system takeover.
Business impact
The CVSS score of 9.9 highlights the extreme risk posed by this vulnerability, which allows an attacker to bypass standard security controls and seize control of the application. The impact includes potential unauthorized access to sensitive staffing and financial records, as well as the risk of lateral movement to other connected PeopleSoft modules. Given the nature of financial software, the potential for data manipulation and unauthorized financial reporting is high.
Remediation
Immediate Action: Apply the relevant security patches released in the July 2026 Oracle Critical Patch Update for the affected PeopleSoft version.
Proactive Monitoring: Monitor access logs for abnormal user behavior, particularly actions taken by low-privileged accounts that deviate from standard workflows.
Compensating Controls: Utilize WAF and network access controls to restrict access to the affected PeopleSoft modules and block suspicious HTTP requests that match known exploitation vectors.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Security teams must prioritize the application of the July 2026 Oracle patches for PeopleSoft environments. Given the potential for full system takeover, failure to patch leaves the organization vulnerable to significant data compromise and operational disruption. Ensure that patching procedures are followed, and verify that the environment is secured against unauthorized network access.