Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-61242: Oracle PeopleSoft 9.1 Staffing Component: Unauthorised Access

CVE-2026-61242
Summary

A security weakness in Oracle PeopleSoft's 9.1 Staffing component allows an attacker to gain control over the system. This could lead to sensitive information being compromised or modified, and the system being disrupted. Update to the latest version to fix this issue.

Original title
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulne...
Original description
Vulnerability in the PeopleSoft Enterprise FIN Common Objects Argentina product of Oracle PeopleSoft (component: Staffing). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Common Objects Argentina. While the vulnerability is in PeopleSoft Enterprise FIN Common Objects Argentina, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Common Objects Argentina. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
nvd CVSS3.1 9.9
Vulnerability type
CWE-284 Improper Access Control
Published: 21 Jul 2026 · Updated: 23 Jul 2026 · First seen: 22 Jul 2026