Junglewise Threat Intelligence

CVE-2026-61204: Oracle PeopleSoft Enterprise FIN Program Management takeover in Primavera Integration

CVE-2026-61204 · Severity: critical · CVSS 9 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle PeopleSoft's financial program management software, specifically within the Primavera Integration component. This software is used by organizations to manage large-scale financial projects and resource planning. An attacker with low-level access could take over the entire application, potentially leading to the theft of sensitive financial data or a complete disruption of business operations. Exploitation requires a legitimate user to perform an action, such as clicking a malicious link.

Technical details

This vulnerability affects the Primavera Integration component of Oracle PeopleSoft Enterprise FIN Program Management version 9.2. It is classified as a high-impact flaw (CVSS 9.0) that allows a low-privileged attacker with network access via HTTP to compromise the system. The attack requires human interaction from a person other than the attacker (UI:R) and results in a scope change (S:C), meaning the security breach can extend beyond the PeopleSoft application to other parts of the environment. Successful exploitation can lead to a complete takeover of the affected product, impacting confidentiality, integrity, and availability. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation.

Affected products

  • Oracle PeopleSoft Enterprise FIN Program Management 9.2

Timeline

  • 2026-07-21: disclosed: Initial disclosure via Oracle Critical Patch Update and NVD publication.

References