Vulnerability in Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager
CVE-2026-61076

9.9CRITICAL

What is CVE-2026-61076?

An improper access control vulnerability exists in Oracle's PeopleSoft Enterprise HCM Talent Acquisition Manager. This flaw allows low privileged attackers with network access via HTTP to exploit the system, potentially leading to a complete takeover of the application. Although primarily affecting the HCM Talent Acquisition Manager, the implications of this vulnerability could extend to other connected products, signifying a broader impact. Organizations utilizing the affected version must take swift action to mitigate potential risks and secure their systems against unauthorized access.

Affected Version(s)

PeopleSoft Enterprise HCM Talent Acquisition Manager 9.2

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.