Vulnerability in Oracle PeopleSoft Enterprise FIN Program Management
CVE-2026-61204

9CRITICAL

What is CVE-2026-61204?

A vulnerability exists in the Oracle PeopleSoft Enterprise FIN Program Management product, specifically within the Primavera Integration component. This flaw allows a low-privileged attacker with network access via HTTP to compromise the system. Exploitation of this vulnerability necessitates human interaction from an individual other than the attacker, potentially broadening the impact across related products. Successful exploitation may lead to complete takeover of the PeopleSoft Enterprise FIN Program Management system, compromising confidentiality, integrity, and availability.

Affected Version(s)

PeopleSoft Enterprise FIN Program Management 9.2

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.