Junglewise Threat Intelligence

CVE-2026-61209: Oracle PeopleSoft In-Memory Project Discovery takeover vulnerability

CVE-2026-61209 · Severity: critical · CVSS 9.9 · Published 2026-07-21

Vendors: Oracle.

Executive brief

A critical vulnerability exists in Oracle PeopleSoft In-Memory Project Discovery, a tool used for project data analysis and visualization. An attacker with basic user access can exploit this flaw over the network to take full control of the system. This could lead to the theft of sensitive project data, unauthorized modification of records, or a complete disruption of the service, potentially impacting other integrated business systems.

Technical details

This vulnerability affects the Project Discovery component of Oracle PeopleSoft In-Memory Project Discovery version 9.2. It is classified as easily exploitable, requiring only low-privileged user credentials and network access via HTTP. The vulnerability is notable for a 'scope change' (Status: Changed in CVSS), meaning a successful exploit can impact components or products beyond the immediate security scope of the affected application. An attacker can achieve full compromise of confidentiality, integrity, and availability, effectively resulting in a complete system takeover. Users are advised to refer to the Oracle Critical Patch Update for July 2026 for remediation steps.

Affected products

  • Oracle PeopleSoft In-Memory Project Discovery 9.2

Timeline

  • 2026-07-21: disclosed: Initial disclosure by Oracle
  • 2026-07-21: advisory: NVD publication date

References