CVE-2026-61209
Oracle · PeopleSoft In-Memory Project Discovery
A critical vulnerability in Oracle PeopleSoft In-Memory Project Discovery allows a low privileged attacker to achieve full system takeover via network-based HTTP requests.
Executive summary
A critical security vulnerability in Oracle PeopleSoft In-Memory Project Discovery allows authenticated attackers to compromise the system and impact broader infrastructure.
Vulnerability
The flaw is located in the Project Discovery component and is easily exploitable by an authenticated user with low privileges. The vulnerability allows for scope changes, meaning an attacker can move beyond the initial component to gain control over the entire system.
Business impact
An attacker successfully exploiting this vulnerability gains the ability to take over the In-Memory Project Discovery product, potentially resulting in the loss of sensitive project data and organizational intellectual property. The high CVSS score of 9.9 confirms that this is a critical threat requiring immediate attention to avoid severe operational and security consequences.
Remediation
Immediate Action: Apply the latest Oracle Critical Patch Update for July 2026 to remediate the vulnerability in the Project Discovery component.
Proactive Monitoring: Monitor for unusual system behavior and unauthorized access attempts targeting the Project Discovery module.
Compensating Controls: Implement strict network access controls and utilize a Web Application Firewall to mitigate potential exploitation attempts while the patch is being deployed.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing PeopleSoft In-Memory Project Discovery must prioritize the application of the July 2026 security patches. Given the potential for complete system takeover, delaying the update significantly increases the risk of successful exploitation by malicious actors.