Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-61209: Oracle PeopleSoft 9.2 Project Discovery Takeover Risk via HTTP

CVE-2026-61209 CVE-2026-61209
Summary

A security issue in Oracle PeopleSoft's Project Discovery feature allows an attacker with network access to potentially take control of the system. This affects version 9.2 of the software. Users should update to a fixed version to prevent unauthorized access.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
oracle corporation peoplesoft in-memory project discovery 9.2
Original title
Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerab...
Original description
Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery. While the vulnerability is in PeopleSoft In-Memory Project Discovery, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft In-Memory Project Discovery. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
nvd CVSS3.1 9.9
Vulnerability type
CWE-269 Improper Privilege Management
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 22 Jul 2026