Junglewise Threat Intelligence

CVE-2026-61076: Oracle PeopleSoft Talent Acquisition Manager takeover in Job Opening component

CVE-2026-61076 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A critical vulnerability has been identified in Oracle PeopleSoft's Talent Acquisition Manager, a tool used by organizations to manage job openings and recruitment processes. An attacker with low-level access to the system can exploit this flaw over the network to gain full control of the application. This could lead to the theft of sensitive employee and applicant data, disruption of hiring operations, and potential unauthorized access to other connected corporate systems.

Technical details

A vulnerability exists in the Job Opening component of Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager version 9.2. The flaw is categorized as easily exploitable and allows a low-privileged attacker with network access via HTTP to compromise the system. Notably, the exploit results in a 'scope change' (CVSS S:C), meaning the impact can extend beyond the Talent Acquisition Manager to other integrated products or the underlying environment. Successful exploitation grants the attacker full control over the application, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation steps.

Affected products

  • Oracle PeopleSoft Enterprise HCM Talent Acquisition Manager 9.2

Timeline

  • 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
  • 2026-07-21: disclosed: NVD published the CVE record.

References