Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-61209: Oracle PeopleSoft 9.2 Project Discovery Takeover Risk via HTTP
CVE-2026-61209
CVE-2026-61209
Summary
A security issue in Oracle PeopleSoft's Project Discovery feature allows an attacker with network access to potentially take control of the system. This affects version 9.2 of the software. Users should update to a fixed version to prevent unauthorized access.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| oracle corporation | peoplesoft in-memory project discovery | 9.2 |
Original title
Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerab...
Original description
Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery. While the vulnerability is in PeopleSoft In-Memory Project Discovery, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft In-Memory Project Discovery. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
nvd CVSS3.1
9.9
Vulnerability type
CWE-269
Improper Privilege Management
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 22 Jul 2026